Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.43% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Media (5.1) | 0.44% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Images in Crestron Automate VX is active, snapshots of the captured video or portions thereof are stored locally on the system, and there is no visible indication that this is… | |
| Analizada | Media (5.7) | 0.90% | — | Microsoft Power Automate FOR Desktop | 15/4/2025 | 17/6/2026 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | |
| Aplazada | Alta (7.2) | 1.0% | — | Database Backup AND Check Tables Automated With SchedulerAI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.59% | — | Database Backup AND Check Tables Automated With Scheduler 2024AI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Media (6) | 0.28% | — | Hcltech Dryice Iautomate | 5/2/2025 | 17/6/2026 | HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session. | |
| Analizada | Media (4.3) | 0.19% | — | Sperse Automate HUB | 24/1/2025 | 17/6/2026 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation on the 'automate_hub' page. This makes it possible for unauthenticated attackers to update an activation status via a… | |
| Analizada | Alta (7.8) | 0.75% | — | Microsoft Power Automate FOR Desktop | 14/1/2025 | 17/6/2026 | Microsoft Power Automate Remote Code Execution Vulnerability | |
| Aplazada | Media (6.1) | 0.48% | — | Sperse.io Automate HUB FreeAI | 7/1/2025 | 17/6/2026 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (4.9) | 0.85% | — | Database Backup AND Check Tables Automated With SchedulerAI | 24/12/2024 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Media (5.9) | 0.66% | — | Automatedlogic WebctrlAI | 21/11/2024 | 17/6/2026 | A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.jsp" | |
| Aplazada | Crítica (10) | 1.4% | — | Automatedlogic WebctrlAI | 21/11/2024 | 17/6/2026 | An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST request which could lead to uploading a malicious file. | |
| Analizada | Alta (8.5) | 0.88% | — | Microsoft Power Automate | 10/9/2024 | 10/8/2026 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability | |
| Aplazada | Media (6.5) | 0.39% | — | AutomatewooAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Woo AutomateWoo.This issue affects AutomateWoo: from n/a through 5.7.5. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Casap Automated Enrollment SystemAIPHPAIMysqliAI | 14/5/2024 | 17/6/2026 | SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component | |
| Aplazada | Alta (7.6) | 0.52% | — | Nasirahmed Forms TO ZapierAINasirahmed Forms TO IntegromatAINasirahmed Forms TO IftttAINasirahmed Forms TO WorkatoAI+5 | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Forms to Zapier, Integromat, IFTTT, Workato, Automate.Io, elastic.Io, Built.Io, APIANT, Webhook.This issue affects Forms to Zapier, Integromat, IFTTT, Workato, Automate.Io, elastic.Io, Built.Io, APIANT,… | |
| Analizada | Media (6.1) | 0.46% | — | Boyiddha Automated-mess-management-system | 8/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. Affected by this issue is some unknown functionality of the file /member/member_edit.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The… | |
| Analizada | Media (6.1) | 0.46% | — | Boyiddha Automated-mess-management-system | 8/3/2024 | 17/6/2026 | A vulnerability classified as problematic was found in boyiddha Automated-Mess-Management-System 1.0. Affected by this vulnerability is an unknown functionality of the file /member/chat.php of the component Chat Book. The manipulation of the argument msg leads to cross site scripting. The attack can be launched… | |
| Analizada | Crítica (9.8) | 0.56% | — | Boyiddha Automated-mess-management-system | 8/3/2024 | 17/6/2026 | A vulnerability classified as critical has been found in boyiddha Automated-Mess-Management-System 1.0. Affected is an unknown function of the file /member/view.php. The manipulation of the argument date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 0.68% | — | Boyiddha Automated-mess-management-system | 8/3/2024 | 17/6/2026 | A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.56% | — | Boyiddha Automated-mess-management-system | 8/3/2024 | 17/6/2026 | A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has… | |
| Modificada | Alta (8.1) | 1.0% | — | Connectwise AutomateConnectwise Screenconnect | 1/2/2024 | 17/6/2026 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. | |
| Modificada | Media (5.5) | 0.45% | — | Connectwise AutomateConnectwise Screenconnect | 1/2/2024 | 17/6/2026 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings | |
| Modificada | Crítica (9.8) | 0.72% | — | Fabian Automated Voting System | 28/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Automated Voting System 1.0. This vulnerability affects unknown code of the component Login. The manipulation of the argument idno leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249130 is the identifier… | |
| Modificada | Alta (8.8) | 0.70% | — | Fabian Automated Voting System | 28/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Automated Voting System 1.0. This affects an unknown part of the file /admin/ of the component Admin Login. The manipulation of the argument username leads to sql injection. The exploit has been disclosed to the public and may be used. The… |