Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
6573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Secufor OauthAI | 24/6/2026 | 25/6/2026 | The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to disconnect the WordPress site from its linked… | |
| Aplazada | Alta (7.2) | 0.36% | — | Email Javascript CloakAI | 24/6/2026 | 25/6/2026 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.76% | — | Broadcom Spring Statemachine | 23/6/2026 | 22/9/2026 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring… | |
| Aplazada | Media (6.5) | 0.60% | — | CboardAI | 23/6/2026 | 5/7/2026 | SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component | |
| Aplazada | Crítica (9.1) | 0.52% | — | Mojolicious Plugin WEB Auth Oauth2AI | 23/6/2026 | 23/6/2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)… | |
| Analizada | Alta (8.8) | 0.48% | — | Joomlaboat Extra Search | 19/6/2026 | 19/8/2026 | Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomlashack Osdownloads | 19/6/2026 | 19/8/2026 | Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Tftp BroadbandAI | 19/6/2026 | 29/9/2026 | TFTP Broadband 4.3.0.1465 contiene una vulnerabilidad de ruta de servicio sin comillas en el binario de servicio tftpt.exe que permite a atacantes locales ejecutar código arbitrario con privilegios de sistema. Los atacantes pueden colocar un ejecutable malicioso en la ruta del directorio Program Files que se ejecutará… | |
| Aplazada | Media (5.3) | 0.46% | — | 2download Connector FOR 2DL Hosted CheckoutAI | 19/6/2026 | 22/6/2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary… | |
| Pendiente de análisis | Media (5.1) | 0.49% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 24/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 22/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own… | |
| Aplazada | Alta (8.8) | 1.1% | — | Offload AI Optimize With Cloudflare ImagesAI | 18/6/2026 | 18/6/2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the… | |
| Aplazada | Alta (8.6) | 0.80% | — | ThingsboardAI | 17/6/2026 | 22/6/2026 | ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN). | |
| Aplazada | Media (6.5) | 0.25% | — | Postman DownloadAI | 17/6/2026 | 22/6/2026 | The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary… | |
| Aplazada | Media (5.5) | 0.32% | — | Yoast SEO PremiumAI | 17/6/2026 | 17/6/2026 | Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Schiocco Support BoardAI | 17/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | |
| Aplazada | Media (6.4) | 0.23% | — | File Sharing Download Manager User Private FilesAI | 16/6/2026 | 17/6/2026 | The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.1) | 0.33% | — | Dancer2 Plugin Auth OauthAI | 15/6/2026 | 17/6/2026 | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable. | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form 7 Drag AND Drop Multiple File UploadAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Easydigitaldownloads Easy Digital DownloadsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. | |
| Aplazada | Media (4.4) | 0.37% | — | Download MonitorAI | 15/6/2026 | 17/6/2026 | Author Arbitrary File Download in Download Monitor <= 5.1.9 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Broadcast Live VideoAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. | |
| Analizada | Alta (7.5) | 0.46% | — | Broadcom Spring Cloud Sleuth | 15/6/2026 | 17/6/2026 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled.… | |
| Aplazada | Crítica (9.8) | 0.77% | — | ThingsboardAI | 15/6/2026 | 17/6/2026 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass… | |
| Aplazada | Media (5.4) | 0.16% | — | Iptanus File UploadAI | 14/6/2026 | 23/7/2026 | El plugin de WordPress Iptanus File Upload anterior a la versión 5.1.7 no implementa un manejo adecuado de archivos cuando la configuración 'duplicatepolicy' está configurada como 'maintain both'. Debido a una condición de carrera de Tiempo de Verificación a Tiempo de Uso (TOCTOU) entre la verificación de existencia… |