Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.53%—Revmakx Backup AND Staging BY WP Time CapsuleAI1/8/202417/6/2026
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.
AplazadaCrítica (9.9)16%💥 PoCDocker-ceAIDocker EEAIDocker EngineAIMirantis Container RuntimeAI24/7/202417/6/2026
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low. Using…
AnalizadaCrítica (9.8)4.9%💥 ExploitEfrotech Timetrax22/7/202417/6/2026
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.
AplazadaCrítica (9.8)2.4%💥 ExploitIntelight X-1l Traffic Controller MaxtimeAI22/7/202417/6/2026
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.
AplazadaMedia (5.9)0.27%—Pratik Chaskar Timeline Module FOR Beaver BuilderAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Timeline Module for Beaver Builder allows Stored XSS.This issue affects Timeline Module for Beaver Builder: from n/a through 1.1.3.
AplazadaAlta (8.8)0.72%—Timeline Event HistoryAI18/7/202417/6/2026
The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted input 'timelines-data' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No…
AplazadaMedia (5.3)0.92%💥 ExploitTimersys WP PopupsAI12/7/202417/6/2026
The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path…
AplazadaAlta (8.2)0.51%—Siemens Simatic PCS 7AISiemens Simatic Wincc Runtime ProfessionalAISiemens Simatic WinccAI9/7/202417/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 23), SIMATIC WinCC V7.5 (All versions…
ModificadaMedia (5.3)0.49%—Zkteco Biotime5/7/202417/6/2026
A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add Handler. The manipulation of the argument user with the input <script>alert('XSS')</script> leads to cross site scripting. It is possible to launch the…
AplazadaAlta (7.2)0.59%—Changingtec Mobile ONE Time PasswordAI1/7/202417/6/2026
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
AplazadaMedia (4.9)0.61%—Changingtec Mobile ONE Time PasswordAI1/7/202417/6/2026
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
AplazadaMedia (6.8)0.38%—Spotfire Enterprise Runtime FOR R - Server EditionAISpotfire Statistics ServicesAISpotfire DesktopAISpotfireAI+127/6/202417/6/2026
Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue…
AnalizadaAlta (7.6)0.26%—Realwebcare Muslim Prayer Time BD26/6/202417/6/2026
The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
AplazadaMedia (6.3)0.36%—Fujitsu ID Link ManagerAIFujitsu Time CreatorAI18/6/202417/6/2026
Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine if a username is valid or not.
AplazadaMedia (6.5)0.44%—Fujitsu ID Link ManagerAIFujitsu Software Time CreatorAI18/6/202417/6/2026
Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be obtained and/or the information stored in the database may be altered by a remote authenticated attacker.
AplazadaAlta (8.6)0.68%—Fujitsu ID Link ManagerAIFujitsu Time CreatorAI18/6/202417/6/2026
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.
AplazadaAlta (7.3)0.54%—TimeticsAI14/6/202417/6/2026
The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including, 1.0.21. This makes it possible for…
ModificadaCrítica (9.8)0.40%—Codepeople WP Time Slots Booking Form10/6/202417/6/2026
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11.
ModificadaAlta (7.5)0.42%—Codepeople WP Time Slots Booking Form9/6/202417/6/2026
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
ModificadaMedia (6.1)0.31%—Codepeople WP Time Slots Booking Form8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10.
AplazadaMedia (4.4)0.27%—Nafeza Prayer TimeAI4/6/202417/6/2026
The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaMedia (6.5)0.32%—Bonitasoft Bonita RuntimeAI15/5/202417/6/2026
In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.
AplazadaAlta (7.2)0.17%—B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+2114/5/202417/6/2026
An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation…
AplazadaAlta (8.2)0.26%—Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+1514/5/202417/6/2026
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software…
AplazadaMedia (5.9)0.44%—Nathan Vonnahme Configure Login TimeoutAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Configure Login Timeout allows Stored XSS.This issue affects Configure Login Timeout: from n/a through 1.0.
Orbitaley — Vulnerabilidades