Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.53% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via the download.php script. The endpoint exposes a file download mechanism that lacks access control, allowing remote, unauthenticated users to request files stored on the… | |
| Analizada | Media (6.9) | 0.46% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the… | |
| Analizada | Crítica (9.3) | 1.1% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates the directory if it… | |
| Analizada | Crítica (9.3) | 0.71% | — | Audiocodes FAX ServerAudiocodes Interactive Voice Response | 19/11/2025 | 17/6/2026 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files/utils/IVR/diagram/ajaxScript.php. The saveScript action writes attacker-supplied data directly to… | |
| Aplazada | Media (4.3) | 0.22% | — | Qodeinteractive QI BlocksAI | 15/11/2025 | 17/6/2026 | The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user has permission to resize a specific attachment. This makes it… | |
| Aplazada | Media (6.5) | 0.16% | — | Qodeinteractive QI BlocksAI | 13/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-blocks allows Stored XSS.This issue affects Qi Blocks: from n/a through <= 1.4.3. | |
| Modificada | Alta (8.1) | 0.57% | — | Qodeinteractive Wanderland | 6/11/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.7.1. | |
| Modificada | Alta (8.1) | 0.62% | — | Qodeinteractive DOR | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.23% | — | Qodeinteractive QI BlocksAI | 1/11/2025 | 17/6/2026 | The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin storing arbitrary CSS styles submitted via the `qi-blocks/v1/update-styles` REST API endpoint without proper sanitization in the `update_global_styles_callback()` function.… | |
| Modificada | Media (5.4) | 0.12% | — | Qodeinteractive Bard | 31/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a through <= 1.6. | |
| Aplazada | Media (5.5) | 0.22% | — | Interactive Human Anatomy With Clickable Body PartsAI | 3/10/2025 | 17/6/2026 | The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (4.3) | 0.14% | — | Tryinteract Interact Quiz EmbedAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tryinteract Interact: Embed A Quiz On Your Site interact-quiz-embed allows Cross Site Request Forgery.This issue affects Interact: Embed A Quiz On Your Site: from n/a through <= 3.1. | |
| Aplazada | Crítica (9.8) | 0.44% | — | BGS Interactive Sinav.linkAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection. This issue affects SINAV.LINK Exam Result Module: before 1.2. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Interactive-git-checkoutAI | 9/9/2025 | 17/6/2026 | The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branch while it prompts for the branch name on the command-line. It is available as an npm package and can be installed via `npm install -g interactive-git-checkout`. Versions up to and including 1.1.4 of… | |
| Aplazada | Media (6.4) | 0.24% | — | Qodeinteractive QI Addons FOR ElementorAI | 2/8/2025 | 17/6/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.26% | — | Qodeinteractive QI Addons FOR Elementor | 28/6/2025 | 17/6/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Grill AND Chow | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6. | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Grandprix | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6. | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Mediclinic | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1. | |
| Aplazada | Media (4.3) | 0.14% | — | Wpmapplugins Interactive Regional MAP OF AfricaAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-africa allows Cross Site Request Forgery.This issue affects Interactive Regional Map of Africa: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Wpmapplugins Interactive UK Regional MAPAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-map allows Cross Site Request Forgery.This issue affects Interactive UK Regional Map: from n/a through <= 2.0. | |
| Aplazada | Media (5.3) | 0.26% | — | Interactive Regional MAP OF FloridaAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida interactive-map-of-florida allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Interactive Regional Map of Florida: from n/a through <= 1.0. | |
| Modificada | Crítica (9.8) | 0.71% | — | Qodeinteractive Wilmer | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.4.2. | |
| Modificada | Alta (8.1) | 0.78% | — | Qodeinteractive Backpack Traveler | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows PHP Local File Inclusion.This issue affects Backpack Traveler: from n/a through <= 2.10.2. | |
| Modificada | Alta (8.1) | 0.73% | — | Qodeinteractive Foton | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Foton foton allows PHP Local File Inclusion.This issue affects Foton: from n/a through <= 2.5.2. |