Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.53% | — | Revmakx Backup AND Staging BY WP Time CapsuleAI | 1/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20. | |
| Aplazada | Crítica (9.9) | 16% | 💥 PoC | Docker-ceAIDocker EEAIDocker EngineAIMirantis Container RuntimeAI | 24/7/2024 | 17/6/2026 | Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low. Using… | |
| Analizada | Crítica (9.8) | 4.9% | 💥 Exploit | Efrotech Timetrax | 22/7/2024 | 17/6/2026 | EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface. | |
| Aplazada | Crítica (9.8) | 2.4% | 💥 Exploit | Intelight X-1l Traffic Controller MaxtimeAI | 22/7/2024 | 17/6/2026 | An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component. | |
| Aplazada | Media (5.9) | 0.27% | — | Pratik Chaskar Timeline Module FOR Beaver BuilderAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Timeline Module for Beaver Builder allows Stored XSS.This issue affects Timeline Module for Beaver Builder: from n/a through 1.1.3. | |
| Aplazada | Alta (8.8) | 0.72% | — | Timeline Event HistoryAI | 18/7/2024 | 17/6/2026 | The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted input 'timelines-data' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No… | |
| Aplazada | Media (5.3) | 0.92% | 💥 Exploit | Timersys WP PopupsAI | 12/7/2024 | 17/6/2026 | The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path… | |
| Aplazada | Alta (8.2) | 0.51% | — | Siemens Simatic PCS 7AISiemens Simatic Wincc Runtime ProfessionalAISiemens Simatic WinccAI | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 23), SIMATIC WinCC V7.5 (All versions… | |
| Modificada | Media (5.3) | 0.49% | — | Zkteco Biotime | 5/7/2024 | 17/6/2026 | A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add Handler. The manipulation of the argument user with the input <script>alert('XSS')</script> leads to cross site scripting. It is possible to launch the… | |
| Aplazada | Alta (7.2) | 0.59% | — | Changingtec Mobile ONE Time PasswordAI | 1/7/2024 | 17/6/2026 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands. | |
| Aplazada | Media (4.9) | 0.61% | — | Changingtec Mobile ONE Time PasswordAI | 1/7/2024 | 17/6/2026 | CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system. | |
| Aplazada | Media (6.8) | 0.38% | — | Spotfire Enterprise Runtime FOR R - Server EditionAISpotfire Statistics ServicesAISpotfire DesktopAISpotfireAI+1 | 27/6/2024 | 17/6/2026 | Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue… | |
| Analizada | Alta (7.6) | 0.26% | — | Realwebcare Muslim Prayer Time BD | 26/6/2024 | 17/6/2026 | The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Aplazada | Media (6.3) | 0.36% | — | Fujitsu ID Link ManagerAIFujitsu Time CreatorAI | 18/6/2024 | 17/6/2026 | Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not. | |
| Aplazada | Media (6.5) | 0.44% | — | Fujitsu ID Link ManagerAIFujitsu Software Time CreatorAI | 18/6/2024 | 17/6/2026 | Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be obtained and/or the information stored in the database may be altered by a remote authenticated attacker. | |
| Aplazada | Alta (8.6) | 0.68% | — | Fujitsu ID Link ManagerAIFujitsu Time CreatorAI | 18/6/2024 | 17/6/2026 | Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker. | |
| Aplazada | Alta (7.3) | 0.54% | — | TimeticsAI | 14/6/2024 | 17/6/2026 | The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including, 1.0.21. This makes it possible for… | |
| Modificada | Crítica (9.8) | 0.40% | — | Codepeople WP Time Slots Booking Form | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11. | |
| Modificada | Alta (7.5) | 0.42% | — | Codepeople WP Time Slots Booking Form | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06. | |
| Modificada | Media (6.1) | 0.31% | — | Codepeople WP Time Slots Booking Form | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10. | |
| Aplazada | Media (4.4) | 0.27% | — | Nafeza Prayer TimeAI | 4/6/2024 | 17/6/2026 | The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (6.5) | 0.32% | — | Bonitasoft Bonita RuntimeAI | 15/5/2024 | 17/6/2026 | In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Aplazada | Alta (8.2) | 0.26% | — | Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+15 | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software… | |
| Aplazada | Media (5.9) | 0.44% | — | Nathan Vonnahme Configure Login TimeoutAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Configure Login Timeout allows Stored XSS.This issue affects Configure Login Timeout: from n/a through 1.0. |