Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
21.609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.59% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by… | |
| Aplazada | Media (5.5) | 0.54% | — | Getgrav Dom-sanitizerAI | 1/10/2026 | 1/10/2026 | A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2) | 0.36% | — | Rhukster DOM SanitizerAI | 1/10/2026 | 6/10/2026 | A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be… | |
| Aplazada | Media (5.3) | 0.18% | — | Geminilabs Site ReviewsAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | |
| Aplazada | Media (5.9) | 0.40% | — | Genian NAC ZtnaAI | 1/10/2026 | 1/10/2026 | A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | |
| Aplazada | Alta (8.4) | 1.9% | — | Genian SSL PNSAI | 1/10/2026 | 1/10/2026 | An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely | |
| Aplazada | Alta (7.5) | 0.23% | — | Genian SSL PNSAI | 1/10/2026 | 1/10/2026 | An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration | |
| Aplazada | Baja (1.8) | 0.10% | — | Genian SSL PNSAI | 1/10/2026 | 1/10/2026 | An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch | |
| Aplazada | Alta (7.3) | 0.31% | — | Genian SSL PNSAI | 1/10/2026 | 1/10/2026 | A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Genian NAC Ztna Policy ServerAI | 1/10/2026 | 1/10/2026 | Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | |
| Aplazada | Alta (7.1) | 0.15% | — | PhotonicAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | |
| Aplazada | Alta (7.8) | 0.13% | — | Reachy Mini ISOAI | 30/9/2026 | 2/10/2026 | Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to… | |
| Aplazada | Media (6.5) | 0.15% | 💥 PoC | Strong TestimonialsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11. | |
| Aplazada | Media (6.5) | 0.21% | — | Creativethemes Blocksy CompanionAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Alta (7.1) | 0.20% | — | Geminilabs Site ReviewsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Minimum AND Maximum Quantity FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ninjaforms Ninja FormsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | |
| Aplazada | Baja (2.7) | 0.17% | — | Media Library OrganizerAI | 30/9/2026 | 30/9/2026 | The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site. | |
| Analizada | Crítica (9.8) | 0.61% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node. | |
| Analizada | Crítica (9.4) | 0.25% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has… | |
| Analizada | Alta (7.5) | 0.31% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service | |
| Analizada | Alta (7.8) | 0.14% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote… | |
| Analizada | Alta (8.8) | 0.18% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node. | |
| Analizada | Alta (7.5) | 0.31% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. |