Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.61% | — | Newtype Flowmaster BPM Plus | 15/10/2024 | 17/6/2026 | The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie. | |
| Analizada | Media (4.9) | 0.60% | — | Teamplus Team+ PRO | 14/10/2024 | 17/6/2026 | The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them. | |
| Analizada | Alta (7.5) | 0.67% | — | Teamplus Team+ PRO | 14/10/2024 | 17/6/2026 | The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. | |
| Analizada | Crítica (9.8) | 0.73% | — | Teamplus Team+ PRO | 14/10/2024 | 17/6/2026 | The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents. | |
| Aplazada | Alta (7.5) | 0.45% | — | Ledvance SmartplusAI | 11/10/2024 | 5/7/2026 | LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Analizada | Media (4.3) | 0.38% | — | Posimyth THE Plus Addons FOR Elementor | 11/10/2024 | 17/6/2026 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 9.0% | 💥 PoC | Jsonpath-plusAI | 11/10/2024 | 17/6/2026 | All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions… | |
| Analizada | Media (5.4) | 0.34% | — | Wpuserplus Userplus | 10/10/2024 | 17/6/2026 | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or… | |
| Analizada | Alta (7.2) | 0.47% | — | Wpuserplus Userplus | 10/10/2024 | 17/6/2026 | The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration form… | |
| Analizada | Crítica (9.8) | 0.52% | — | Wpuserplus Userplus | 10/10/2024 | 17/6/2026 | The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role'… | |
| Aplazada | Crítica (9.3) | 0.17% | — | Himed Cockpit 12 PROAIHimed Cockpit 14 PRO PlusAIHimed Cockpit 18 PROAIHimed Cockpit 18 PRO PlusAI | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro+ (J31032-K2017-H436)… | |
| Aplazada | Crítica (9.3) | 0.59% | — | TEM Opera Plus FMAI | 3/10/2024 | 17/6/2026 | TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTTP2 web server module but is also used by the SNMP module and is available to other applications that require basic… | |
| Aplazada | Alta (8.6) | 0.24% | — | TEM Opera Plus FM Family TransmitterAI | 3/10/2024 | 17/6/2026 | The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site. | |
| Aplazada | Media (6.5) | 0.48% | — | Zohocorp Manageengine Analytics PlusAIZoho Analytics On-premiseAI | 3/10/2024 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. | |
| Analizada | Media (5.4) | 0.32% | — | Kraftplugins Demo Importer Plus | 2/10/2024 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Media (5.3) | 0.22% | — | Devfelixmoira Limit Login Attempts Plus | 19/9/2024 | 17/6/2026 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header… | |
| Modificada | Media (5.4) | 0.29% | — | Posimyth THE Plus Addons FOR Elementor | 17/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 5.6.2. | |
| Analizada | Media (5.3) | 0.20% | — | Rfideas Micard Plus CI FirmwareRfideas Micard Plus BLE Firmware | 16/9/2024 | 17/6/2026 | The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration and might result in… | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Media (5.9) | 0.43% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Analizada | Media (5.4) | 0.30% | — | Wp-brandtheme Preloader Plus | 7/9/2024 | 17/6/2026 | The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Modificada | Alta (7.5) | 0.43% | — | Fujitsu Ipcom VE2 LS 100 FirmwareFujitsu Ipcom VE2 LS 200 FirmwareFujitsu Ipcom VE2 LS 220 FirmwareFujitsu Ipcom VE2 LS Plus 100 Firmware+15 | 4/9/2024 | 17/6/2026 | Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. If this vulnerability is exploited, some of the encrypted communication may be decrypted by an attacker who can… | |
| Analizada | Alta (7.5) | 0.66% | — | Zyxel Nebula Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa710 FirmwareZyxel Nebula Fwa510 Firmware+46 | 3/9/2024 | 17/6/2026 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Analizada | Alta (7.8) | 0.16% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+164 | 2/9/2024 | 17/6/2026 | Memory corruption while processing IOCTL call for getting group info. |