Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.34% | — | Mariadb Model Context Protocol | 10/9/2025 | 17/6/2026 | An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation. | |
| Aplazada | Media (6.5) | 0.36% | — | Pankaj.sakaria CMS BlocksAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in pankaj.sakaria CMS Blocks cms-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMS Blocks: from n/a through <= 1.1. | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field "Profisso" (professor). | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript. | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function. | |
| Modificada | Media (6.1) | 0.26% | 💥 PoC | Jetimob Imobiliaria | 10/6/2025 | 5/7/2026 | Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the "Pessoas" (persons) section when creating or editing either a legal or a natural person. | |
| Aplazada | Alta (8.6) | 0.50% | — | Wpopal Opal WOO Custom Product VariationAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-custom-product-variation allows Path Traversal.This issue affects Opal Woo Custom Product Variation: from n/a through <= 1.2.0. | |
| Analizada | Alta (8.2) | 0.34% | — | Vmware Aria AutomationVmware Cloud FoundationVmware Telco Cloud Platform | 13/5/2025 | 17/6/2026 | VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL. | |
| Aplazada | Media (5.4) | 0.33% | — | Gsplugins GS Variation Swatches FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Variation Swatches for WooCommerce gs-woo-variation-swatches allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Variation Swatches for WooCommerce: from n/a through <= 3.0.4. | |
| Modificada | Crítica (9.8) | 0.32% | — | Multidots Advanced Linked Variations FOR Woocommerce | 22/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for Woocommerce: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | Ip2location VariablesAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in IP2Location IP2Location Variables ip2location-variables allows Reflected XSS.This issue affects IP2Location Variables: from n/a through <= 2.9.5. | |
| Aplazada | Media (5.9) | 0.40% | — | Aria FontAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in آریا وردپرس Aria Font aria-font allows Stored XSS.This issue affects Aria Font: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.43% | — | Bowo Variable InspectorAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Bowo Variable Inspector variable-inspector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Variable Inspector: from n/a through <= 2.6.3. | |
| Aplazada | Media (4.3) | 0.43% | — | Anzar Ahmed Display Product Variations Dropdown ON Shop PageAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page display-product-variations-dropdown-on-shop-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display product variations dropdown on shop page: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.8) | 0.15% | — | Vmware Aria OperationsAI | 1/4/2025 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations. | |
| Aplazada | Media (4.3) | 0.23% | — | Shaharia Azam Auto Post After Image UploadAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Shaharia Azam Auto Post After Image Upload auto-post-after-image-upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Post After Image Upload: from n/a through <= 1.6. | |
| Aplazada | Media (4.9) | 0.50% | — | Mariadb ServerAI | 8/3/2025 | 17/6/2026 | MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan. | |
| Aplazada | Media (4.9) | 0.46% | — | Mariadb ServerAI | 8/3/2025 | 17/6/2026 | MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where. | |
| Aplazada | Media (4.9) | 0.47% | — | Mariadb ServerAI | 8/3/2025 | 17/6/2026 | MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2. | |
| Aplazada | Media (4.9) | 0.43% | — | Mariadb ServerAI | 8/3/2025 | 17/6/2026 | MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash. | |
| Aplazada | Alta (7.1) | 0.32% | — | Bowo Variable InspectorAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector variable-inspector allows Reflected XSS.This issue affects Variable Inspector: from n/a through <= 2.6.2. | |
| Aplazada | Media (6.5) | 0.37% | — | Codingkart WOO Update Variations IN CartAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codingkart Woo Update Variations In Cart woo-update-variations-in-cart allows Stored XSS.This issue affects Woo Update Variations In Cart: from n/a through <= 0.0.9. | |
| Aplazada | Media (4.3) | 0.15% | — | Alex Prokopenko Just-wp-variablesAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just Variables just-wp-variables allows Cross Site Request Forgery.This issue affects Just Variables: from n/a through <= 1.2.3. | |
| Aplazada | Crítica (9.8) | 0.90% | — | Alvaria Unified IP Unified DirectorAI | 14/2/2025 | 17/6/2026 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component. | |
| Aplazada | Alta (7.1) | 0.28% | — | Ariagle Wp-clapAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ariagle WP-Clap wp-clap allows Reflected XSS.This issue affects WP-Clap: from n/a through <= 1.5. |