Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.26% | — | Administrative ShortcodesAI | 24/1/2026 | 17/6/2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'login' and 'logout' shortcode attributes in all versions up to, and including, 0.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.8) | 0.33% | — | Svenstaro Miniserve | 23/1/2026 | 17/6/2026 | A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared… | |
| Aplazada | Media (5.5) | 0.26% | — | Amministrazione TrasparenteAI | 31/8/2025 | 17/6/2026 | The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Media (4.5) | 0.11% | — | Malwarebytes Binisoft Windows Firewall ControlAI | 28/7/2025 | 17/6/2026 | In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation. | |
| Analizada | Alta (8.5) | 0.14% | — | Siemens TIA Administrator | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and exceute arbitrary code. | |
| Analizada | Media (6.9) | 0.07% | — | Siemens TIA Administrator | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker to bypass the check and exceute arbitrary code during installations. | |
| Aplazada | Media (6.1) | 0.25% | — | SAP Businessobjects Content Administrator WorkbenchAI | 8/7/2025 | 17/6/2026 | Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality and integrity, with no… | |
| Modificada | Media (5.5) | 0.17% | — | Redhat Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackInfinispan | 26/6/2025 | 17/6/2026 | A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found. | |
| Aplazada | Alta (7) | 0.36% | — | Tibco Activematrix AdministratorAI | 21/5/2025 | 17/6/2026 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application. | |
| Analizada | Media (4.8) | 0.34% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 15/5/2025 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Aplazada | Media (5.4) | 0.14% | — | Intel Network Adapters Administrative ToolsAI | 13/5/2025 | 17/6/2026 | Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.9) | 0.69% | — | QUY LE 91 Administrator ZAI | 16/4/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Quý Lê 91 Administrator Z administrator-z allows Path Traversal.This issue affects Administrator Z: from n/a through <= 2025.03.28. | |
| Aplazada | Alta (8.8) | 0.37% | — | QUY LE 91 Administrator ZAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue affects Administrator Z: from n/a through <= 2025.03.24. | |
| Aplazada | Media (4.3) | 0.15% | — | QUY LE 91 Administrator ZAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z administrator-z allows Cross Site Request Forgery.This issue affects Administrator Z: from n/a through <= 2026.03.02. | |
| Aplazada | Media (6.5) | 0.40% | — | QUY LE 91 Administrator ZAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quý Lê 91 Administrator Z administrator-z allows DOM-Based XSS.This issue affects Administrator Z: from n/a through <= 2026.03.02. | |
| Aplazada | Media (6.5) | 0.49% | — | InfinispanAIRedhat Data GridAI | 28/3/2025 | 26/6/2026 | A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API. | |
| Aplazada | Alta (8.8) | 0.36% | — | Administrator ZAI | 28/3/2025 | 17/6/2026 | The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminz_import_backup() function in all versions up to, and including, 2025.03.24. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.9) | 0.36% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Innovacion Y Cualificacion Local Administration PluginAI | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’, ‘searchSpecialitiesPending’, ‘searchSpecialitiesLinked’,… | |
| Aplazada | Alta (8.7) | 0.56% | — | Siemens Simatic PCS NEOAISiemens Simocode ESAISiemens Sirius Safety ESAISiemens Sirius Soft Starter ESAI+1 | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES… | |
| Analizada | Baja (2.3) | 0.72% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (6.3) | 0.80% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The… | |
| Analizada | Baja (3.4) | 0.69% | — | Haxx CurlNetapp H700s FirmwareNetapp H615c FirmwareNetapp H610s Firmware+12 | 5/2/2025 | 17/6/2026 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. | |
| Aplazada | Media (5.5) | 0.21% | — | InfinispanAIJgroupsAI | 28/1/2025 | 17/6/2026 | A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors. | |
| Aplazada | Media (4.3) | 0.47% | — | Inisev Social Media & Share IconsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media & Share Icons: from n/a through 2.8.1. |