Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4531 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | Flashyapp WP Flashy Marketing AutomationAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Flashyapp WP Flashy Marketing Automation wp-flashy-marketing-automation allows Cross Site Request Forgery.This issue affects WP Flashy Marketing Automation: from n/a through <= 2.0.8. | |
| Aplazada | Media (4.3) | 0.13% | — | Valerio Monti Auto ALT TextAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Valerio Monti Auto Alt Text auto-alt-text allows Cross Site Request Forgery.This issue affects Auto Alt Text: from n/a through <= 2.5.2. | |
| Aplazada | Media (5.3) | 0.32% | — | Talent Software E-bap AutomationAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS). This issue affects e-BAP Automation: from 1.8.96 before v.41815. | |
| Aplazada | Alta (8.8) | 0.52% | — | Auto ThumbnailerAI | 5/12/2025 | 17/6/2026 | The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the… | |
| Aplazada | Media (6.4) | 0.29% | 💥 PoC | AutoptimizeAI | 3/12/2025 | 17/6/2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, 3.1.13 due to insufficient input sanitization and output escaping on user-supplied image attributes in the "create_img_preload_tag" function. This makes it… | |
| Analizada | Crítica (9.1) | 0.41% | — | Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware | 2/12/2025 | 25/9/2026 | Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity. | |
| Analizada | Media (4) | 0.07% | — | Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware | 2/12/2025 | 25/9/2026 | Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes. | |
| Analizada | Crítica (9.8) | 0.46% | — | Sprecher-automation Sprecon-e-c FirmwareSprecher-automation Sprecon-e-p FirmwareSprecher-automation Sprecon-e-t3 Firmware | 2/12/2025 | 25/9/2026 | Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance. | |
| Aplazada | Alta (8.7) | 0.33% | — | Carrier Zone ControllerAIAutomatedlogic Zone ControllerAI | 27/11/2025 | 17/6/2026 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed. | |
| Aplazada | Alta (8.8) | 0.34% | — | Carrier I-vu Gen5 RouterAIAutomatedlogic I-vu Gen5 RouterAI | 27/11/2025 | 17/6/2026 | — | |
| Aplazada | Media (6.9) | 0.31% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser . | |
| Aplazada | Crítica (9.2) | 0.33% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server. | |
| Aplazada | Media (5.3) | 0.27% | — | Autochat Automatic ConversationAI | 25/11/2025 | 17/6/2026 | The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to connect and disconnect… | |
| Aplazada | Media (4.3) | 0.26% | — | Uncannyowl Uncanny AutomatorAI | 21/11/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0. | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Media (5.4) | 0.12% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter not being sanitized. | |
| Aplazada | Alta (8.6) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions. | |
| Aplazada | Media (6.1) | 0.25% | — | WP Twitter Auto PublishAI | 18/11/2025 | 17/6/2026 | The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (7.1) | 0.16% | — | Rockwellautomation Arena | 14/11/2025 | 7/10/2026 | Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a… | |
| Aplazada | Alta (8.1) | 0.37% | — | Optimus Brokerage AutomationAI | 14/11/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information. This issue affects… | |
| Aplazada | Media (6.5) | 0.13% | — | Ramon Fincken Auto-prune-postsAI | 13/11/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affects Auto Prune Posts: from n/a through <= 3.0.0. | |
| Aplazada | Media (6.9) | 0.58% | — | AutomgenAI | 12/11/2025 | 16/6/2026 | AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through… | |
| Analizada | Alta (7.8) | 0.16% | — | Autodesk 3DS MAX | 12/11/2025 | 17/6/2026 | A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.17% | — | Autodesk 3DS MAX | 12/11/2025 | 17/6/2026 | A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |