Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.24% | — | Apache Streampark | 12/12/2025 | 17/6/2026 | Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to… | |
| Analizada | Crítica (9.8) | 0.48% | — | Apache Streampark | 12/12/2025 | 17/6/2026 | In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through… | |
| Aplazada | Media (5.3) | 0.37% | — | Campay Woocommerce Payment GatewayAI | 12/12/2025 | 17/6/2026 | The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly validating that a transaction has occurred through the payment gateway. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.18% | — | HCL Unica CampaignAI | 13/10/2025 | 17/6/2026 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website. | |
| Modificada | Alta (7.3) | 0.55% | — | Apache Streampark | 10/10/2025 | 17/6/2026 | Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | |
| Modificada | Alta (7.6) | 0.59% | — | Apache Streampark | 22/8/2025 | 17/6/2026 | SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. It can… | |
| Analizada | Media (5.6) | 0.25% | — | JLY Campaignevents | 3/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: from 1.43.X before 1.43.2. | |
| Aplazada | Crítica (10) | 5.5% | 💥 Exploit | Stamparm MaltrailAI | 2/7/2025 | 17/6/2026 | An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoint. This occurs due to unsafe handling of user-supplied input passed to… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Enersys AmpaAI | 9/5/2025 | 17/6/2026 | EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access. | |
| Aplazada | Crítica (9.8) | 1.5% | — | Enersys AmpaAI | 9/5/2025 | 17/6/2026 | EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access. | |
| Aplazada | Media (5.9) | 0.41% | — | Activecampaign-subscription-formsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign activecampaign-subscription-forms allows Stored XSS.This issue affects ActiveCampaign: from n/a through <= 8.1.16. | |
| Aplazada | Alta (8.8) | 0.47% | — | AmpacheAI | 5/3/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0. | |
| Analizada | Media (4.6) | 0.31% | — | Teampasswordmanager Team Password Manager | 4/3/2025 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page. | |
| Analizada | Media (6.9) | 0.62% | — | 1000projects Campaign Management System Platform FOR Women | 17/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.62% | — | 1000projects Campaign Management System Platform FOR Women | 17/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely.… | |
| Aplazada | Media (5.4) | 0.46% | — | Pravin Durugkar User Sync ActivecampaignAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign registered-user-sync-activecampaign allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Sync ActiveCampaign: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.37% | — | Optimize Your Campaigns Google Shopping Google ADS Google AdwordsAI | 7/1/2025 | 17/6/2026 | The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to extract sensitive… | |
| Aplazada | Media (5.3) | 0.34% | — | Popup Mailchimp Getresponse AND Activecampaign IntergrationsAI | 7/1/2025 | 17/6/2026 | The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'upc_delete_db_data' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to delete the… | |
| Analizada | Alta (8.1) | 0.47% | — | Teampass | 30/12/2024 | 17/6/2026 | TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. | |
| Analizada | Media (5.3) | 0.31% | — | Teampass | 30/12/2024 | 17/6/2026 | TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. | |
| Analizada | Media (4.3) | 0.34% | — | Teampass | 30/12/2024 | 17/6/2026 | TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. | |
| Aplazada | Media (6.1) | 0.35% | — | Campaign Monitor Forms BY Optin CATAI | 3/12/2024 | 17/6/2026 | The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Crítica (9) | 0.51% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript. This issue has been… | |
| Analizada | Media (5.3) | 0.28% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users send messages to one another. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to send messages to any user,… | |
| Analizada | Media (5.3) | 0.28% | — | Ampache | 11/11/2024 | 17/6/2026 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to delete messages to any user, including… |