Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.5% | — | Siemens Opcenter Execution FoundationAISiemens Opcenter IntelligenceAISiemens Opcenter QualityAISiemens Opcenter RdnlAI+3 | 16/12/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),… | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Really-simple-plugins Really Simple Security | 15/11/2024 | 17/6/2026 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.29% | — | Omarfolgheraiter DigitallyAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omarfolghe Digitally digitally allows Reflected XSS.This issue affects Digitally: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.25% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.5. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Siemens Opcenter QualityAISiemens Opcenter RdnlAISiemens Simatic PCS NEOAISiemens Sinec NMSAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client… | |
| Aplazada | Media (4.3) | 0.18% | — | Mythemeshop SociallyviralAI | 12/7/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop SociallyViral.This issue affects SociallyViral: from n/a through 1.0.10. | |
| Analizada | Media (4.8) | 0.28% | — | Accessally Popupally | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1. | |
| Aplazada | Crítica (9.4) | 0.48% | — | Baxter Welch Allyn Configuration ToolAI | 31/5/2024 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior. | |
| Aplazada | Crítica (9.1) | 0.39% | — | Baxter Welch Allyn Connex Spot MonitorAI | 31/5/2024 | 17/6/2026 | Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot Monitor in all versions prior to 1.52. | |
| Aplazada | Alta (8.2) | 0.26% | — | Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+15 | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software… | |
| Modificada | Media (4.8) | 0.36% | — | Accessally Popupally | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1. | |
| Aplazada | Media (5.5) | 0.33% | — | Really-simple-plugins Really Simple SSLAI | 18/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3. | |
| Modificada | Media (4.3) | 0.34% | — | Accessally Popupally | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0. | |
| Modificada | Media (4.3) | 0.20% | — | Really-simple-plugins Complianz | 2/3/2024 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Media (4.8) | 0.32% | — | Really-simple-plugins Complianz | 4/1/2024 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Alta (8.1) | 0.48% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0. | |
| Modificada | Alta (7.5) | 0.91% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (7.5) | 0.91% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (7.5) | 0.91% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Media (6.1) | 0.49% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (8.8) | 0.94% | — | Siemens Opcenter QualitySiemens Simatic PCS NEOSiemens Sinumerik Integrate Runmyhmi /automotiveSiemens Totally Integrated Automation Portal | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal… | |
| Modificada | Alta (8.8) | 0.34% | — | Really-simple-plugins Complianz | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7. | |
| Modificada | Alta (8.8) | 0.31% | — | Really-simple-plugins Complianz | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6.4.6.1. | |
| Modificada | Alta (7.2) | 0.68% | — | Cagewebdev Order Your Posts Manually | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Order Your Posts Manually allows SQL Injection.This issue affects Order Your Posts Manually: from n/a through 2.2.5. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… |