Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1919 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 1.2% | — | Pfsense PlusAIPfsense CEAI | 19/8/2026 | 23/9/2026 | pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator… | |
| Aplazada | Media (6.5) | 0.22% | — | Featured Video PlusAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Wppa WP Photo Album PlusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Wppa WP Photo Album PlusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options… | |
| Aplazada | Alta (7.5) | 0.38% | — | WpphotoalbumplusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored… | |
| Aplazada | Media (6.1) | 0.26% | — | Wppa WP Photo Album PlusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page… | |
| Pendiente de análisis | Alta (8.5) | 1.8% | — | Zohocorp Manageengine M365 Manager PlusAIZohocorp Manageengine M365 Security PlusAI | 11/8/2026 | 31/8/2026 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. | |
| Aplazada | Media (5.3) | 0.32% | — | Wppa WP Photo Album PlusAI | 9/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores. | |
| Aplazada | Media (5.3) | 0.33% | — | Featured Video PlusAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | |
| Aplazada | Baja (1.9) | 0.14% | — | Textplus Text Message AND Call APPAI | 3/8/2026 | 12/8/2026 | A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly… | |
| Aplazada | Media (6.1) | 0.25% | — | Wppa WP Photo Album PlusAI | 31/7/2026 | 26/8/2026 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by… | |
| Aplazada | Alta (8.7) | 0.46% | — | RCU II PlusAIMultiload II PlusAI | 30/7/2026 | 8/9/2026 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication,… | |
| Aplazada | Media (4.9) | 0.60% | — | Wppa WP Photo Album PlusAI | 29/7/2026 | 30/7/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.2) | 1.2% | — | Wordplus Better MessagesAI | 28/7/2026 | 28/7/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.66% | — | CP Plus Ez-p21AI | 27/7/2026 | 27/7/2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain… | |
| Aplazada | Alta (7) | 0.23% | 💥 PoC | CP Plus Ez-p21AI | 27/7/2026 | 27/7/2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this… | |
| Pendiente de análisis | Crítica (10) | 4.7% | — | Zohocorp Manageengine Adaudit PlusAI | 23/7/2026 | 24/7/2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | |
| Aplazada | Baja (2.1) | 0.37% | — | Zsadmin2025 Zs-adminAIMybatis-plusAI | 21/7/2026 | 23/7/2026 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be… | |
| Pendiente de análisis | Alta (7.1) | 1.2% | — | Zohocorp Manageengine Adselfservice PlusAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. | |
| Aplazada | Media (6.5) | 0.27% | — | Payplus Payment GatewayAI | 20/7/2026 | 21/7/2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses. | |
| Aplazada | Media (5.3) | 0.29% | — | Payplus Payment GatewayAI | 20/7/2026 | 21/7/2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. | |
| Aplazada | Alta (7.7) | 0.15% | — | Sandboxie PlusAI | 15/7/2026 | 16/7/2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the sandboxed process… | |
| Analizada | Alta (8.8) | 0.53% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+2 | 15/7/2026 | 11/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process,… | |
| Analizada | Media (6.3) | 0.45% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This… | |
| Analizada | Alta (8.3) | 0.42% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control… |