Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.40% | — | Mayurik PET Grooming Management Software | 8/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file add_user.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (6.5) | 0.23% | — | Webcodingplace Woocommerce Coming Soon Product With CountdownAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows Stored XSS.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through <= 5.0. | |
| Analizada | Alta (7.5) | 0.35% | — | Hsiaoming Joserfc | 3/3/2026 | 17/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library decrypts a JSON Web… | |
| Aplazada | Alta (7.5) | 0.49% | — | Webcodingplace Woocommerce Coming Soon Product With CountdownAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows PHP Local File Inclusion.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a… | |
| Aplazada | Media (5.3) | 0.30% | — | Seedprod Coming Soon Page Under Construction Maintenance ModeAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.8. | |
| Analizada | Baja (2) | 0.56% | — | Mingsoft Mcms | 18/2/2026 | 17/6/2026 | A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published… | |
| Analizada | Baja (2) | 0.60% | — | Qnap Media Streaming Add-on | 11/2/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: Media Streaming… | |
| Analizada | Baja (1.7) | 0.11% | — | Qnap Media Streaming Add-on | 11/2/2026 | 17/6/2026 | An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later | |
| Analizada | Baja (2.1) | 0.40% | — | Mayurik PET Grooming Management Software | 30/1/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/user.php of the component User Management. Performing a manipulation of the argument group_id results in improper authorization. The attack can be initiated remotely. The… | |
| Analizada | Alta (7.5) | 0.42% | — | Sick Incoming Goods Suite | 15/1/2026 | 17/6/2026 | Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover… | |
| Analizada | Media (5.3) | 0.46% | — | Sick Incoming Goods Suite | 15/1/2026 | 17/6/2026 | The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components. | |
| Analizada | Alta (7.5) | 0.54% | — | Sick Incoming Goods Suite | 15/1/2026 | 17/6/2026 | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access. | |
| Aplazada | Media (6.5) | 0.15% | — | Jcaruso001 Flaming-password-resetAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming Password Reset flaming-password-reset allows Stored XSS.This issue affects Flaming Password Reset: from n/a through <= 1.0.3. | |
| Aplazada | Alta (8.8) | 0.30% | — | Aa-team Premium AGE Verification / Restriction FOR WordpressAIAa-team Responsive Coming Soon Landing Page / Holding Page FOR WordpressAI | 6/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive… | |
| Aplazada | Media (4.3) | 0.27% | — | Boomdevs Wordpress Coming SoonAI | 31/12/2025 | 28/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPress Coming Soon coming-soon-by-boomdevs allows Retrieve Embedded Sensitive Data.This issue affects BoomDevs WordPress Coming Soon: from n/a through <= 1.0.4. | |
| Modificada | Alta (8.6) | 0.78% | — | Ateme Flamingo XL Firmware | 30/12/2025 | 17/6/2026 | Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment. | |
| Modificada | Crítica (9.3) | 0.65% | — | Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem | 30/12/2025 | 24/9/2026 | Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | |
| Analizada | Alta (7.5) | 0.33% | — | Libming | 29/12/2025 | 17/6/2026 | Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8. | |
| Analizada | Alta (7.5) | 0.33% | — | Libming | 29/12/2025 | 7/10/2026 | Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8. | |
| Aplazada | Alta (7.5) | 1.9% | 💥 Exploit | HummingbirdAI | 18/12/2025 | 1/10/2026 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials. | |
| Aplazada | Media (4.3) | 0.16% | — | Upcoming FOR CalendlyAI | 12/12/2025 | 17/6/2026 | The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Calendly API key via a forged… | |
| Analizada | Media (4.8) | 0.40% | — | HP Omen Gaming HUBHP System Event Utility | 9/12/2025 | 17/6/2026 | HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2.12 and Omen Gaming Hub version 1101.2511.101.0. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file. |