Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4531 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 0.14% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot. | |
| Aplazada | Alta (8.9) | 0.17% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes. | |
| Aplazada | Alta (7.5) | 0.46% | — | Michaeluno Auto Amazon LinksAI | 11/11/2025 | 17/6/2026 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary… | |
| Aplazada | Media (4.4) | 0.19% | — | Squirrels Auto InventoryAI | 11/11/2025 | 7/10/2026 | The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Alta (8.8) | 0.52% | — | Smart Auto Upload ImagesAI | 8/11/2025 | 7/10/2026 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creation functionality in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload… | |
| Aplazada | Media (6.1) | 0.21% | — | Wp2social Auto PublishAI | 8/11/2025 | 7/10/2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (4.9) | 0.31% | — | TAG Category AND Taxonomy Manager AI Autotagger With OpenaiAI | 8/11/2025 | 7/10/2026 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Alta (7.8) | 0.20% | — | Autodesk Shared Components | 7/11/2025 | 7/10/2026 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.16% | — | Autodesk Installer | 6/11/2025 | 7/10/2026 | A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM. | |
| Analizada | Media (6.1) | 0.21% | — | IBM Business Automation WorkflowIBM Process Federation Server | 6/11/2025 | 17/6/2026 | IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an… | |
| Analizada | Media (4.3) | 0.19% | — | Hcltech Dryice Iautomate | 5/11/2025 | 17/6/2026 | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see. | |
| Analizada | Media (4.3) | 0.26% | — | Funnelkit Automations | 5/11/2025 | 17/6/2026 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying that a user is authorized to perform administrative actions in the… | |
| Analizada | Media (5.3) | 0.37% | — | Funnelkit Automations | 5/11/2025 | 17/6/2026 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is due to the endpoint being marked as a public API (`public_api =… | |
| Aplazada | Media (4.3) | 0.19% | — | AI Auto Tool Content Writing AssistantAI | 4/11/2025 | 17/6/2026 | The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+132 | 4/11/2025 | 17/6/2026 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. | |
| Analizada | Media (6.1) | 0.08% | — | Qualcomm Msm8996au FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qam8620p Firmware+34 | 4/11/2025 | 17/6/2026 | Information disclosure while processing message from client with invalid payload. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Apq8064au FirmwareQualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform Firmware+91 | 4/11/2025 | 17/6/2026 | Memory corruption while processing a GP command response. | |
| Analizada | Alta (7.8) | 0.06% | — | Qualcomm Qcs615 FirmwareQualcomm Qcs6490 FirmwareQualcomm Qcs8300 FirmwareQualcomm Qcs8550 Firmware+171 | 4/11/2025 | 17/6/2026 | Memory corruption while performing encryption and decryption commands. | |
| Analizada | Media (6.1) | 0.08% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform Firmware+73 | 4/11/2025 | 17/6/2026 | Information disclosure while registering commands from clients with diag through diagHal. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to… | |
| Analizada | Alta (7.4) | 0.27% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls. | |
| Analizada | Media (6.5) | 0.45% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Cloud PAK FOR Business Automation | 3/11/2025 | 17/6/2026 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment. | |
| Aplazada | Alta (7.5) | 0.34% | — | Autobizline 2ND LineAI | 30/10/2025 | 17/6/2026 | 2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., contains an improper access control vulnerability in its authentication mechanism. The server only validates the first character of the user_token, enabling attackers to brute force tokens and perform… | |
| Aplazada | Media (5.9) | 0.18% | — | Automattic WoocommerceAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce woocommerce allows Stored XSS.This issue affects WooCommerce: from n/a through <= 10.0.2. |