Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Analizada | Alta (7.5) | 0.45% | — | Opensourcepos Open Source Point OF Sale | 18/11/2025 | 17/6/2026 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns… | |
| Analizada | Baja (2.1) | 0.37% | — | Jkev Dental Clinic Appointment Reservation System | 17/11/2025 | 7/10/2026 | Se detectó una vulnerabilidad en el Sistema de Reserva de Citas para Clínica Dental SourceCodester 1.0. Se ve afectada una función desconocida del archivo /success.PHP. La manipulación del argumento username/password resulta en inyección SQL. El ataque puede iniciarse de forma remota. El exploit es ahora público y… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpswings Woocommerce Ultimate Points AND RewardsAI | 13/11/2025 | 7/10/2026 | Exposición de Información Sensible del Sistema a una Esfera de Control No Autorizada vulnerabilidad en WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards permite Recuperar Datos Sensibles Incrustados. Este problema afecta a WooCommerce Ultimate Points And Rewards: desde n/a hasta… | |
| Aplazada | Media (5.4) | 0.20% | — | Codepeople Appointment Booking CalendarAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad por Autorización Faltante en codepeople Appointment Booking Calendar appointment-booking-calendar permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a Appointment Booking Calendar: desde n/a hasta menor o igual que 1.3.95. | |
| Analizada | Alta (8) | 2.1% | — | Microsoft Sharepoint Server | 11/11/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.24% | — | Ivanti Endpoint Manager | 11/11/2025 | 17/6/2026 | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk | |
| Analizada | Media (6.8) | 0.10% | — | Bitdefender Endpoint Security | 11/11/2025 | 17/6/2026 | An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass the configured uninstall password protection. An unauthorized user with sudo privileges can manually remove the application directory… | |
| Aplazada | Media (6.5) | 0.26% | — | Easyappointments Easy AppointmentsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14. | |
| Analizada | Media (5.3) | 0.22% | — | Salesforce Mulesoft Anypoint Code Builder | 4/11/2025 | 17/6/2026 | Vulnerabilidad de Asignación Incorrecta de Permisos para Recurso Crítico en Salesforce Mulesoft Anypoint Code Builder permite manipular archivos de configuración escribibles. Este problema afecta a Mulesoft Anypoint Code Builder: antes de la 1.11.6. | |
| Analizada | Media (5.3) | 0.24% | — | Salesforce Mulesoft Anypoint Code Builder | 4/11/2025 | 17/6/2026 | La vulnerabilidad de neutralización inadecuada de la entrada utilizada para el prompting de LLM en Salesforce Mulesoft Anypoint Code Builder permite manipular archivos de configuración escribibles. Este problema afecta a Mulesoft Anypoint Code Builder: antes de la versión 1.11.6. | |
| Analizada | Media (6.5) | 0.21% | — | Salesforce Mulesoft Anypoint Code Builder | 4/11/2025 | 17/6/2026 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6. | |
| Analizada | Baja (2.3) | 0.63% | — | Proofpoint Insider Threat Management Server | 3/11/2025 | 17/6/2026 | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from… | |
| Analizada | Media (6.1) | 0.22% | — | Sailpoint Identityiq | 3/11/2025 | 17/6/2026 | IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to… | |
| Analizada | Baja (2) | 0.36% | — | Janobe Point OF Sales | 27/10/2025 | 8/10/2026 | Se ha descubierto una falla de seguridad en SourceCodester Point of Sales 1.0. Se ve afectada una función desconocida del archivo /delete_category.php. La manipulación del argumento ID resulta en inyección SQL. El ataque puede iniciarse remotamente. El exploit ha sido publicado y puede ser explotado. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Point OF Sales | 27/10/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en SourceCodester Point of Sales 1.0. Este problema afecta a un procesamiento desconocido del archivo /category.php. Dicha manipulación del argumento Category conduce a inyección SQL. Es posible lanzar el ataque de forma remota. El exploit está disponible públicamente y podría ser… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Point OF Sales | 27/10/2025 | 8/10/2026 | Se determinó una vulnerabilidad en SourceCodester Point of Sales 1.0. Esta vulnerabilidad afecta código desconocido del archivo /index.php. Esta manipulación del argumento Username causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser utilizado. | |
| Analizada | Media (4.3) | 0.52% | — | Zohocorp Manageengine Endpoint Central | 27/10/2025 | 8/10/2026 | Las versiones de ZohoCorp ManageEngine Endpoint Central anteriores a la 11.4.2528.05 son vulnerables a un problema de registro de información sensible. Un usuario autenticado con acceso a los registros podría potencialmente obtener el token de agente sensible. | |
| Aplazada | Alta (7.3) | 0.18% | — | Langchain Langgraph-checkpoint-sqliteAILangchainAI | 26/10/2025 | 17/6/2026 | A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct… | |
| Aplazada | Media (6.5) | 0.18% | — | Themepoints TAB UltimateAI | 22/10/2025 | 8/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Themepoints Tab Ultimate tabs-pro. Este problema afecta a Tab Ultimate: desde n/a hasta menor o igual que 1.8. | |
| Aplazada | Alta (7.1) | 0.30% | — | GappointmentsAI | 22/10/2025 | 8/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en wpcrunch gAppointments gAppointments permite XSS Reflejado. Este problema afecta a gAppointments: desde n/a hasta menor o igual que 1.14.1. | |
| Aplazada | Alta (8.8) | 0.63% | — | Phpscriptpoint InsuranceAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de deserialización de datos no confiables en designthemes Insurance insurance permite la inyección de objetos. Este problema afecta a Insurance: desde n/a hasta menor o igual que 3.5. | |
| Analizada | Baja (3.3) | 0.26% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. |