Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.27%—Gopiplus Twitter Real Time Search ScrollingAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Twitter real time search scrolling twitter-real-time-search-scrolling allows Reflected XSS.This issue affects Twitter real time search scrolling: from n/a through <= 7.0.
AplazadaAlta (7.1)0.27%—Sanjay Prasad LoginplusAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanjay Prasad Loginplus loginplus allows Stored XSS.This issue affects Loginplus: from n/a through <= 1.2.
AnalizadaAlta (8.1)2.4%—Zohocorp Manageengine Sharepoint Manager Plus8/11/202417/6/2026
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
AnalizadaAlta (8.8)6.2%💥 ExploitZohocorp Manageengine Admanager Plus8/11/202417/6/2026
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
AnalizadaMedia (4.3)0.41%—G5plus Ultimate Bootstrap Elements FOR Elementor5/11/202417/6/2026
The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive…
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Exchange Reporter Plus5/11/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
AnalizadaMedia (4.8)0.37%—Dublue Table OF Contents Plus5/11/202417/6/2026
The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaAlta (8.8)3.2%—Zohocorp Manageengine Adaudit Plus4/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
AnalizadaAlta (8.8)3.2%—Zohocorp Manageengine Admanager Plus4/11/202417/6/2026
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
AnalizadaAlta (7.8)0.10%—Qualcomm Snapdragon W5+ GEN 1 Wearable Platform FirmwareQualcomm Snapdragon 8+ GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 8+ GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform (sm4350-ac) Firmware+1154/11/202417/6/2026
Memory corruption during GNSS HAL process initialization.
AnalizadaAlta (7.8)0.10%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1744/11/202417/6/2026
Memory corruption while handling session errors from firmware.
AnalizadaMedia (6.7)0.10%—Qualcomm Wsa8835 FirmwareQualcomm Wsa8832 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 Firmware+654/11/202417/6/2026
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
ModificadaAlta (8.8)0.56%—Posimyth THE Plus Addons FOR Elementor1/11/202417/6/2026
Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 5.6.2.
ModificadaMedia (6.1)0.31%—Chatplusjp29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chatplusjp chatplusjp chatplusjp allows Reflected XSS.This issue affects chatplusjp: from n/a through <= 1.02.
AplazadaMedia (6.4)0.36%—Climaxthemes Kata PlusAI29/10/202417/6/2026
The Kata Plus – Addons for Elementor – Widgets, Extensions and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
ModificadaMedia (5.4)0.27%—Climaxthemes Kata Plus28/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata Plus kata-plus allows DOM-Based XSS.This issue affects Kata Plus: from n/a through <= 1.4.7.
AplazadaMedia (6.9)0.39%—Vimesa Vhf/fm Transmitter Blue PlusAI24/10/202417/6/2026
VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.
ModificadaMedia (5.4)0.28%—Spiffyplugins WP Flow Plus24/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.3.
AnalizadaAlta (8.1)2.5%—Zohocorp Manageengine Adaudit Plus24/10/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
ModificadaAlta (8.8)0.21%—Dublue Table OF Contents Plus20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Table of Contents Plus table-of-contents-plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through <= 2408.
AnalizadaMedia (5.1)0.37%—Topdata Inner REP Plus18/10/202417/6/2026
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been rated as problematic. Affected by this issue is some unknown functionality of the file td.js.gz. The manipulation leads to risky cryptographic algorithm. The attack may be launched remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.1)0.49%—Topdata Inner REP Plus18/10/202417/6/2026
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file /InnerRepPlus.html of the component Operator Details Form. The manipulation leads to missing password field masking. It is possible to launch the attack remotely. The…
AplazadaMedia (6.1)0.32%—Wppa WP Photo Album PlusAI17/10/202417/6/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (8.3)0.27%—Wpleadplus WP Lead Plus XAI16/10/202417/6/2026
The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.99. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform administrative actions, such as adding pages to the site…
AnalizadaAlta (8.8)0.65%—Newtype Flowmaster BPM Plus15/10/202417/6/2026
The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.
Orbitaley — Vulnerabilidades