Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

6573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.40%—Secufor OauthAI24/6/202625/6/2026
The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to disconnect the WordPress site from its linked…
AplazadaAlta (7.2)0.36%—Email Javascript CloakAI24/6/202625/6/2026
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.76%—Broadcom Spring Statemachine23/6/202622/9/2026
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring…
AplazadaMedia (6.5)0.60%—CboardAI23/6/20265/7/2026
SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component
AplazadaCrítica (9.1)0.52%—Mojolicious Plugin WEB Auth Oauth2AI23/6/202623/6/2026
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)…
AnalizadaAlta (8.8)0.48%—Joomlaboat Extra Search19/6/202619/8/2026
Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the…
AnalizadaAlta (8.8)0.49%—Joomlashack Osdownloads19/6/202619/8/2026
Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database…
Pendiente de análisisAlta (8.5)0.17%—Tftp BroadbandAI19/6/202629/9/2026
TFTP Broadband 4.3.0.1465 contiene una vulnerabilidad de ruta de servicio sin comillas en el binario de servicio tftpt.exe que permite a atacantes locales ejecutar código arbitrario con privilegios de sistema. Los atacantes pueden colocar un ejecutable malicioso en la ruta del directorio Program Files que se ejecutará…
AplazadaMedia (5.3)0.46%—2download Connector FOR 2DL Hosted CheckoutAI19/6/202622/6/2026
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary…
Pendiente de análisisMedia (5.1)0.49%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202624/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access…
Pendiente de análisisAlta (8.7)0.72%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202622/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own…
AplazadaAlta (8.8)1.1%—Offload AI Optimize With Cloudflare ImagesAI18/6/202618/6/2026
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the…
AplazadaAlta (8.6)0.80%—ThingsboardAI17/6/202622/6/2026
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).
AplazadaMedia (6.5)0.25%—Postman DownloadAI17/6/202622/6/2026
The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary…
AplazadaMedia (5.5)0.32%—Yoast SEO PremiumAI17/6/202617/6/2026
Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.
AplazadaCrítica (9.8)0.48%—Schiocco Support BoardAI17/6/202617/6/2026
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
AplazadaMedia (6.4)0.23%—File Sharing Download Manager User Private FilesAI16/6/202617/6/2026
The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.1)0.33%—Dancer2 Plugin Auth OauthAI15/6/202617/6/2026
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
AplazadaAlta (7.1)0.25%—Contact Form 7 Drag AND Drop Multiple File UploadAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions.
AplazadaAlta (7.5)0.35%—Easydigitaldownloads Easy Digital DownloadsAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
AplazadaMedia (4.4)0.37%—Download MonitorAI15/6/202617/6/2026
Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
AplazadaCrítica (9.8)0.56%—Broadcast Live VideoAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
AnalizadaAlta (7.5)0.46%—Broadcom Spring Cloud Sleuth15/6/202617/6/2026
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled.…
AplazadaCrítica (9.8)0.77%—ThingsboardAI15/6/202617/6/2026
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass…
AplazadaMedia (5.4)0.16%—Iptanus File UploadAI14/6/202623/7/2026
El plugin de WordPress Iptanus File Upload anterior a la versión 5.1.7 no implementa un manejo adecuado de archivos cuando la configuración 'duplicatepolicy' está configurada como 'maintain both'. Debido a una condición de carrera de Tiempo de Verificación a Tiempo de Uso (TOCTOU) entre la verificación de existencia…