Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.69% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.php, user input is reflected without sanitization only when a search returns exactly one product. This flaw bypasses… | |
| Aplazada | Media (4.8) | 0.24% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can inject malicious JavaScript payloads into multiple fields during the creation or modification of a product. These payloads are stored in… | |
| Aplazada | Alta (7.2) | 0.45% | — | CubecartAI | 13/5/2026 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_admin, and sort_customer) of the Products and Logs endpoints in CubeCart v6.x. This allows an attacker to execute… | |
| Analizada | Media (5.1) | 0.44% | — | Cubecart | 17/4/2026 | 17/6/2026 | A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should not be accessible. | |
| Analizada | Media (5.1) | 0.33% | — | Cubecart | 17/4/2026 | 17/6/2026 | An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. | |
| Analizada | Alta (8.6) | 1.2% | — | Cubecart | 17/4/2026 | 17/6/2026 | An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command. | |
| Analizada | Alta (8.2) | 0.55% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. | |
| Analizada | Media (5.3) | 0.51% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. | |
| Analizada | Media (5.3) | 0.53% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Analizada | Media (5.3) | 0.53% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Analizada | Media (4.2) | 0.31% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. | |
| Analizada | Media (6.5) | 0.39% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. | |
| Analizada | Media (6.1) | 0.35% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. | |
| Analizada | Baja (3.1) | 0.36% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. | |
| Analizada | Alta (7.5) | 0.60% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. | |
| Aplazada | Alta (7.5) | 0.55% | — | Flexcubed PitchprintAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal.This issue affects PitchPrint: from n/a through <= 11.1.2. | |
| Analizada | Media (6.9) | 0.58% | — | Ec-cube | 5/3/2026 | 17/6/2026 | EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page. | |
| Aplazada | Alta (7.5) | 1.6% | — | Ioncube Tester PlusAI | 5/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-tester-plus allows Path Traversal.This issue affects ionCube tester plus: from n/a through <= 1.3. | |
| Aplazada | Media (4.7) | 0.53% | — | Roundcube WebmailAI | 11/2/2026 | 17/6/2026 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled. | |
| Analizada | Alta (7.7) | 0.40% | — | Cube.js | 9/2/2026 | 17/6/2026 | Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to privilege escalation. This vulnerability is fixed in 1.5.13, 1.4.2, and 1.0.14. | |
| Analizada | Media (6.5) | 0.45% | — | Cube.js | 9/2/2026 | 17/6/2026 | Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2. | |
| Aplazada | Media (4.3) | 0.48% | — | Roundcube WebmailAI | 9/2/2026 | 17/6/2026 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage. | |
| Aplazada | Media (4.3) | 0.22% | — | CubewpAI | 25/1/2026 | 17/6/2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the search feature in class-cubewp-search-ajax-hooks.php due to insufficient restrictions on which posts can be included. This makes it possible for… | |
| Analizada | Media (6.5) | 0.29% | — | Oracle Flexcube Universal Banking | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Relationship Pricing). Supported versions that are affected are 14.0.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.1) | 0.30% | — | Oracle Flexcube Investor Servicing | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 14.5.0.15.0, 14.7.0.8.0 and 14.8.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via… |