Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.48% | — | Brandexponents OshineAI | 8/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in brandexponents Oshine allows PHP Local File Inclusion. This issue affects Oshine: from n/a before 7.3.0. | |
| Modificada | Alta (7.1) | 0.22% | — | Themegoods Grand Restaurant | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9. | |
| Aplazada | Crítica (9.8) | 1.9% | 💥 Exploit | Wpmudev BrandaAI | 2/1/2026 | 17/6/2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's… | |
| Analizada | Alta (7.5) | 0.41% | 💥 PoC | Inmusicbrands Engine DJ Desktop | 30/12/2025 | 17/6/2026 | inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths. | |
| Aplazada | Media (5.1) | 0.26% | — | Legrand Bticino Driver Manager F454AI | 24/12/2025 | 17/6/2026 | Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET… | |
| Aplazada | Alta (8.5) | 0.25% | — | Berocket Brands FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8.6.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Premmerce Brands FOR WoocommerceAI | 12/12/2025 | 7/10/2026 | The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveBrandsSettings function in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Baja (2) | 0.23% | — | Grandstream Gxp1625AI | 7/12/2025 | 7/10/2026 | A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the file /cgi-bin/api.values.post of the component Network Status Page. Performing manipulation of the argument vpn_ip results in basic cross site scripting. Remote exploitation of the attack is possible.… | |
| Aplazada | Media (6.5) | 0.26% | — | Quadlayers Perfect Brands FOR WoocommerceAI | 24/11/2025 | 17/6/2026 | The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions up to, and including, 3.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (5.5) | 0.19% | — | RandomquotrAI | 11/11/2025 | 7/10/2026 | The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Analizada | Alta (7.1) | 0.19% | — | Themegoods Grand Conference | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Reflected XSS.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4. | |
| Aplazada | Media (4.3) | 0.14% | — | Premmerce Brands FOR WoocommerceAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Brands for WooCommerce premmerce-woocommerce-brands allows Cross Site Request Forgery.This issue affects Premmerce Brands for WooCommerce: from n/a through <= 1.2.13. | |
| Analizada | Baja (2.1) | 0.29% | — | Ajayrandhawa User-management-php-mysql | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in ajayrandhawa User-Management-PHP-MYSQL web up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This vulnerability affects unknown code. Performing manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and… | |
| Analizada | Baja (2) | 0.57% | — | Ajayrandhawa User-management-php-mysql | 27/10/2025 | 17/6/2026 | A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part of the file /admin/edit-user.php of the component User Management Interface. Such manipulation of the argument image leads to unrestricted upload. It is possible to… | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface. | |
| Analizada | Crítica (9.9) | 0.50% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen. | |
| Analizada | Media (5.8) | 0.51% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders. | |
| Analizada | Media (5.8) | 0.38% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path. | |
| Analizada | Alta (7.7) | 0.54% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers. | |
| Analizada | Crítica (9.9) | 0.72% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation. | |
| Analizada | Alta (7.7) | 0.46% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users. | |
| Analizada | Alta (8.6) | 0.32% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages. | |
| Analizada | Alta (8.6) | 0.49% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account. | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 30/9/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume. | |
| Analizada | Alta (7.5) | 0.40% | — | Arandasoft Passrecovery | 26/9/2025 | 17/6/2026 | An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1. |