Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
2620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.25% | — | Funnelforms FreeAI | 24/12/2025 | 7/10/2026 | Vulnerabilidad de falta de autorización en Funnelforms Funnelforms Free funnelforms-free permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Funnelforms Free: desde n/a hasta menor o igual que 3.8. | |
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Free Shipping BAR Amount Left FOR Free Shipping FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce permite XSS Almacenado. Este problema afecta a Free Shipping Bar: Amount Left for Free… | |
| Aplazada | Alta (7.3) | 0.18% | — | Msp360 Free BackupAI | 23/12/2025 | 17/6/2026 | MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.5) | 0.56% | — | Free5gc | 18/12/2025 | 17/6/2026 | The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNode.Sess() when a… | |
| Analizada | Alta (7.5) | 0.44% | — | Free5gc | 18/12/2025 | 17/6/2026 | An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request. | |
| Aplazada | Baja (3.2) | 0.11% | — | Debian FreedomboxAI | 18/12/2025 | 17/6/2026 | Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases. | |
| Analizada | Media (6.6) | 0.24% | — | Freerdp | 17/12/2025 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache filenames without… | |
| Analizada | Alta (8.6) | 6.4% | — | Sangoma Freepbx | 16/12/2025 | 7/10/2026 | El módulo tts (Text to Speech) de FreePBX para FreePBX, una interfaz gráfica de usuario (GUI) basada en web de código abierto que gestiona Asterisk. Las versiones anteriores a la 16.0.5 y 17.0.5 son vulnerables a inyección SQL por usuarios autenticados con acceso de administrador. Los usuarios autenticados con acceso… | |
| Analizada | Media (5.7) | 0.13% | — | Sangoma Freepbx | 16/12/2025 | 7/10/2026 | FreePBX es una interfaz gráfica de usuario (GUI) de código abierto basada en web que gestiona Asterisk. Antes de las versiones 16.0.45 y 17.0.24 del framework de FreePBX, existe una escalada de privilegios local autenticada en el script de inicio obsoleto de FreePBX 'amportal'. En la utilidad obsoleta 'amportal', la… | |
| Analizada | Alta (8.7) | 3.6% | — | Sangoma Freepbx | 11/12/2025 | 17/6/2026 | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell… | |
| Aplazada | Media (6.9) | 0.27% | — | Freepbx Endpoint ManagerAI | 10/12/2025 | 25/9/2026 | FreePBX Endpoint Manager es un módulo para gestionar endpoints de telefonía en sistemas FreePBX. Versiones anteriores a 16.0.96 y 17.0.1 hasta 17.0.9 tienen una contraseña predeterminada débil. Por defecto, este es un valor numérico de 6 dígitos que puede ser forzado por fuerza bruta. (Este es el parámetro… | |
| Analizada | Media (6.5) | 0.30% | — | Freeimage Project Freeimage | 10/12/2025 | 17/6/2026 | An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted PSD file. | |
| Analizada | Crítica (9.3) | 3.3% | 💥 Exploit | Sangoma Freepbx | 9/12/2025 | 25/9/2026 | FreePBX Endpoint Manager es un módulo para gestionar endpoints de telefonía en sistemas FreePBX. Las versiones son vulnerables a omisión de autenticación cuando el tipo de autenticación está configurado como 'webserver'. Al proporcionar un encabezado de autorización con un valor arbitrario, se asocia una sesión con el… | |
| Aplazada | Media (5.3) | 0.33% | — | Bertha AI FreeAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad por falta de autorización en berthaai BERTHA AI bertha-ai-free permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a BERTHA AI: desde n/a hasta menor o igual a 1.13. | |
| Aplazada | Media (6.1) | 0.21% | — | Linkwhisper Link Whisper FreeAI | 6/12/2025 | 17/6/2026 | The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (7.5) | 0.35% | — | Free5gc | 24/11/2025 | 17/6/2026 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API. | |
| Analizada | Media (6.5) | 0.36% | — | Free5gc | 24/11/2025 | 17/6/2026 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API. | |
| Analizada | Media (6.5) | 0.24% | — | Free5gc | 24/11/2025 | 17/6/2026 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API. | |
| Aplazada | Media (6.1) | 0.21% | — | Artibot Free Chat BOT FOR WebsitesAI | 18/11/2025 | 17/6/2026 | The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Baja (3.5) | 0.11% | — | Freebox V5 HD FirmwareFreebox V5 Crystal FirmwareFreebox V6 Revolution FirmwareFreebox Mini 4K Firmware+1 | 17/11/2025 | 17/6/2026 | Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over… | |
| Aplazada | Baja (2.1) | 0.29% | — | Bestfeng OA GIT FreeAI | 15/11/2025 | 7/10/2026 | Se ha identificado una debilidad en bestfeng oa_git_free hasta 9.5. Esto afecta a la función updateWriteBack del archivo yimioa-oa9.5\servidor\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. Esta manipulación del argumento writeProp provoca una referencia a entidad externa XML. El… | |
| Analizada | Alta (7.5) | 0.40% | — | Free5gc | 12/11/2025 | 17/6/2026 | free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes. | |
| Aplazada | Media (4.4) | 0.12% | — | Avast Free AntivirusAI | 11/11/2025 | 17/6/2026 | Collision in MiniFilter driver in Avast Software Avast Free Antivirus before 25.9 on Windows allows a local attacker with administrative privileges to disable real-time protection and self-defense mechanisms. | |
| Aplazada | Media (6.4) | 0.22% | — | Mindstien MY GEO Posts FreeAI | 11/11/2025 | 17/6/2026 | The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, 1.2. This is due to the plugin not properly sanitizing user input or escaping output of the 'default' shortcode attribute. This makes it possible for… | |
| Aplazada | Media (4.4) | 0.19% | — | Free QuotationAI | 4/11/2025 | 17/6/2026 | The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… |