Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.8) | 0.19% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure. | |
| Analizada | Baja (3.7) | 0.28% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content. | |
| Analizada | Media (6.5) | 0.17% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information. | |
| Analizada | Alta (7.6) | 0.25% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information. | |
| Analizada | Alta (7.5) | 0.30% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthorized Actor. | |
| Analizada | Crítica (9.6) | 0.26% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Analizada | Baja (3.3) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies. | |
| Analizada | Media (4.1) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm. | |
| Analizada | Crítica (10) | 0.31% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Cozyvision SMS Alert Order NotificationsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5. | |
| Aplazada | Media (5.3) | 0.38% | — | SitealertAI | 3/10/2025 | 17/6/2026 | The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.9.8. This makes it possible for unauthenticated attackers to view the site health information, including a list of… | |
| Aplazada | Media (4.3) | 0.14% | — | Metin Sarac Popup FOR CF7 With Sweet AlertAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metin Saraç Popup for CF7 with Sweet Alert cf7-sweet-alert-popup allows Cross Site Request Forgery.This issue affects Popup for CF7 with Sweet Alert: from n/a through <= 1.6.5. | |
| Aplazada | Media (6.5) | 0.31% | — | Alertenterprise GuardianAI | 22/7/2025 | 17/6/2026 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the… | |
| Aplazada | Alta (7.3) | 0.38% | — | Alertenterprise GuardianAI | 22/7/2025 | 17/6/2026 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the following build numbers:… | |
| Aplazada | Alta (7.3) | 0.38% | — | Alertenterprise GuardianAI | 22/7/2025 | 17/6/2026 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the following build numbers:… | |
| Analizada | Crítica (9.4) | 0.60% | — | Netalertx | 4/7/2025 | 17/6/2026 | NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification using SHA-256 magic hashes, due to loose comparison in PHP. In vulnerable versions of the application, a password comparison is performed… | |
| Aplazada | Alta (8.1) | 0.58% | — | John Russell National Weather Service AlertsAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Russell National Weather Service Alerts national-weather-service-alerts allows PHP Local File Inclusion.This issue affects National Weather Service Alerts: from n/a through <= 1.3.5. | |
| Aplazada | Media (5) | 0.46% | — | GrafanaAIPrometheus AlertmanagerAIPrometheusAI | 2/6/2025 | 17/6/2026 | This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources… | |
| Analizada | Crítica (9.8) | 0.58% | — | Netalertx | 27/5/2025 | 17/6/2026 | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has… | |
| Aplazada | Alta (8.2) | 0.39% | — | Chimpstudio Jobhunt JOB AlertsAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6. | |
| Analizada | Alta (8.6) | 70% | 💥 Exploit | Netalertx | 13/5/2025 | 17/6/2026 | NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php. | |
| Analizada | Crítica (10) | 62% | 💥 Exploit | Netalertx | 13/5/2025 | 17/6/2026 | NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php. | |
| Modificada | Crítica (9.8) | 0.38% | — | Cozyvision SMS Alert Order Notifications | 12/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.1. | |
| Analizada | Media (5.4) | 0.28% | — | Cozyvision SMS Alert Order Notifications | 10/5/2025 | 17/6/2026 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.46% | — | Cozyvision SMS Alert Order Notifications | 10/5/2025 | 17/6/2026 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level… |