Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1919 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)1.2%—Pfsense PlusAIPfsense CEAI19/8/202623/9/2026
pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator…
AplazadaMedia (6.5)0.22%—Featured Video PlusAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
AplazadaMedia (4.3)0.25%—Wppa WP Photo Album PlusAI12/8/202626/8/2026
The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator.…
AplazadaAlta (7.5)0.43%—Wppa WP Photo Album PlusAI12/8/202626/8/2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options…
AplazadaAlta (7.5)0.38%—WpphotoalbumplusAI12/8/202626/8/2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored…
AplazadaMedia (6.1)0.26%—Wppa WP Photo Album PlusAI12/8/202626/8/2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page…
Pendiente de análisisAlta (8.5)1.8%—Zohocorp Manageengine M365 Manager PlusAIZohocorp Manageengine M365 Security PlusAI11/8/202631/8/2026
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
AplazadaMedia (5.3)0.32%—Wppa WP Photo Album PlusAI9/8/202626/8/2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
AplazadaMedia (5.3)0.33%—Featured Video PlusAI6/8/202612/8/2026
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
AplazadaBaja (1.9)0.14%—Textplus Text Message AND Call APPAI3/8/202612/8/2026
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly…
AplazadaMedia (6.1)0.25%—Wppa WP Photo Album PlusAI31/7/202626/8/2026
WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by…
AplazadaAlta (8.7)0.46%—RCU II PlusAIMultiload II PlusAI30/7/20268/9/2026
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication,…
AplazadaMedia (4.9)0.60%—Wppa WP Photo Album PlusAI29/7/202630/7/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (7.2)1.2%—Wordplus Better MessagesAI28/7/202628/7/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.7)0.66%—CP Plus Ez-p21AI27/7/202627/7/2026
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain…
AplazadaAlta (7)0.23%💥 PoCCP Plus Ez-p21AI27/7/202627/7/2026
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this…
Pendiente de análisisCrítica (10)4.7%—Zohocorp Manageengine Adaudit PlusAI23/7/202624/7/2026
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
AplazadaBaja (2.1)0.37%—Zsadmin2025 Zs-adminAIMybatis-plusAI21/7/202623/7/2026
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be…
Pendiente de análisisAlta (7.1)1.2%—Zohocorp Manageengine Adselfservice PlusAI21/7/202621/7/2026
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
AplazadaMedia (6.5)0.27%—Payplus Payment GatewayAI20/7/202621/7/2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
AplazadaMedia (5.3)0.29%—Payplus Payment GatewayAI20/7/202621/7/2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
AplazadaAlta (7.7)0.15%—Sandboxie PlusAI15/7/202616/7/2026
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the sandboxed process…
AnalizadaAlta (8.8)0.53%—F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+215/7/202611/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process,…
AnalizadaMedia (6.3)0.45%—F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF15/7/202610/8/2026
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This…
AnalizadaAlta (8.3)0.42%—F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF15/7/202610/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control…
Orbitaley — Vulnerabilidades