Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.21% | — | Softpulseinfotech SP Blog DesignerAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Blog Designer: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.37% | — | Brainpulse Page Health-o-meterAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainpulse Page Health-O-Meter page-health-o-meter allows Reflected XSS.This issue affects Page Health-O-Meter: from n/a through <= 2.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Sendpulse Email Marketing NewsletterAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.1.5. | |
| Modificada | Media (6.5) | 0.23% | — | Pulseextensions Altra Side Menu | 27/1/2025 | 17/6/2026 | The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack | |
| Analizada | Alta (7.2) | 0.62% | — | Pulseextensions Altra Side Menu | 27/1/2025 | 17/6/2026 | The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Alta (8.7) | 30% | 💥 Exploit | Laravel Pulse | 13/12/2024 | 17/6/2026 | Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the… | |
| Aplazada | Alta (7.5) | 0.64% | — | Softpulseinfotech SP Blog DesignerAI | 28/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0. | |
| Analizada | Media (4) | 0.30% | — | Pulseaudio | 23/11/2024 | 17/6/2026 | Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected. | |
| Aplazada | Crítica (10) | 1.6% | 💥 PoC | Softpulseinfotech PicsmizeAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sendpulse Free WEB PushAI | 17/10/2024 | 17/6/2026 | The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to incorrect use of the wp_kses_allowed_html function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a… | |
| Analizada | Alta (7.8) | 0.97% | — | Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client | 3/5/2024 | 17/6/2026 | Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Media (5.5) | 0.28% | — | Canonical Ubuntu Pipewire-pulse | 24/1/2024 | 17/6/2026 | Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. | |
| Modificada | Crítica (9.1) | 0.84% | — | Netscout Ngeniuspulse | 7/12/2023 | 17/6/2026 | NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability | |
| Modificada | Crítica (9.8) | 1.5% | — | Netscout Ngeniuspulse | 7/12/2023 | 17/6/2026 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. | |
| Modificada | Crítica (9.8) | 0.71% | — | Netscout Ngeniuspulse | 7/12/2023 | 17/6/2026 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. | |
| Modificada | Alta (8.8) | 0.21% | — | Sendpulse Free WEB Push | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SendPulse SendPulse Free Web Push plugin <= 1.3.1 versions. | |
| Modificada | Crítica (9.8) | 0.68% | — | Varta Element Backup FirmwareVarta Element S1 FirmwareVarta Element S2 FirmwareVarta Element S3 Firmware+4 | 23/3/2023 | 17/6/2026 | Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. | |
| Modificada | Media (5.4) | 45% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 30/9/2022 | 17/6/2026 | Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this… | |
| Modificada | Alta (7.2) | 2.7% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 12/8/2022 | 17/6/2026 | In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role. | |
| Modificada | Alta (7.5) | 1.2% | — | Libpulse-binding Project Libpulse-binding | 27/12/2021 | 17/6/2026 | An issue was discovered in the libpulse-binding crate before 2.6.0 for Rust. It mishandles a panic that crosses a Foreign Function Interface (FFI) boundary. | |
| Modificada | Alta (7.5) | 1.1% | — | Libpulse-binding Project Libpulse-binding | 27/12/2021 | 17/6/2026 | An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_context can cause a use-after-free. | |
| Modificada | Alta (7.5) | 1.3% | — | Libpulse-binding Project Libpulse-binding | 27/12/2021 | 17/6/2026 | An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_format_info can cause a use-after-free. | |
| Modificada | Alta (7.5) | 2.2% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 19/11/2021 | 17/6/2026 | A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device. | |
| Modificada | Alta (7.2) | 2.1% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 16/8/2021 | 17/6/2026 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console. | |
| Modificada | Alta (7.2) | 7.8% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 16/8/2021 | 17/6/2026 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface. |