Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
401.925 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.19% | — | Villatheme CurcyAI | 5/10/2026 | 6/10/2026 | Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. | |
| Recibida | Media (5.4) | 0.17% | — | Brainstormforce Astra SitesAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Recibida | Alta (7.8) | 0.11% | — | Zephyr RtosAI | 5/10/2026 | 5/10/2026 | The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data… | |
| Recibida | Alta (8.4) | 0.10% | — | NXP ZephyrAI | 5/10/2026 | 5/10/2026 | The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the… | |
| Recibida | Crítica (9.3) | 0.78% | — | Totolink A3002muAI | 5/10/2026 | 5/10/2026 | A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Media (5.1) | 0.23% | — | ShaarliAI | 5/10/2026 | 5/10/2026 | A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The… | |
| Recibida | Baja (2.1) | 0.20% | — | Itsourcecode Online Admission SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability was identified in itsourcecode Online Admission System 1.0. Impacted is an unknown function of the file /admin/schoolyear.php. Such manipulation of the argument sy leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Recibida | Media (5.5) | 0.26% | — | Itsourcecode Online Admission SystemAI | 5/10/2026 | 5/10/2026 | A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Recibida | Media (5.3) | 0.25% | — | VgmstreamAI | 5/10/2026 | 5/10/2026 | A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named… | |
| Recibida | Media (6.5) | 0.13% | — | Nikki Blight QR RedirectorAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5. | |
| Recibida | Media (5.3) | 0.20% | — | Pixelite Events ManagerAI | 5/10/2026 | 5/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5. | |
| Recibida | Media (6.5) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/10/2026 | 5/10/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Recibida | Media (4.3) | 0.16% | — | Brandtoss WP Admin AuditAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17. | |
| Recibida | Media (6.5) | 0.13% | — | Themepoints Logo ShowcaseAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4. | |
| Recibida | Media (6.5) | 0.13% | — | Implecode Ecommerce Product CatalogAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | |
| Recibida | Media (5.3) | 0.19% | — | Wpmailster WP MailsterAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. | |
| Recibida | Alta (8.4) | 0.19% | — | — | 5/10/2026 | 5/10/2026 | DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal… | |
| Recibida | Alta (8.4) | 0.35% | — | Mitel Mivoice Office 400AI | 5/10/2026 | 5/10/2026 | This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is… | |
| Recibida | Alta (8.4) | 0.09% | — | Mitel Linux Virtual MachineAI | 5/10/2026 | 5/10/2026 | DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object… | |
| Recibida | Baja (1.9) | 0.25% | — | — | 5/10/2026 | 5/10/2026 | DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application. The specific flaw exists within the web portal listening on TCP port 443,… | |
| Recibida | Baja (1.9) | 0.25% | — | — | 5/10/2026 | 5/10/2026 | DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in… | |
| Recibida | Media (5.5) | 0.31% | — | — | 5/10/2026 | 5/10/2026 | DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate… | |
| Recibida | Alta (8.5) | 0.22% | — | — | 5/10/2026 | 5/10/2026 | DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly… | |
| Recibida | Alta (8.4) | 0.14% | — | — | 5/10/2026 | 5/10/2026 | DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs | |
| Recibida | Media (4.3) | 0.17% | — | Stellarwp Event TicketsAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. |