Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.16% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Cross Site Request Forgery.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 3.8.0. | |
| Analizada | Crítica (9.8) | 0.34% | — | Blyssprivacy Spiral-rs | 24/5/2025 | 17/6/2026 | In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type). | |
| Aplazada | Media (5.3) | 0.51% | — | Kingdee Cloud Galaxy Private Cloud BBC SystemAI | 21/5/2025 | 17/6/2026 | A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file fileUpload/deleteFileAction.jhtml of the component File Handler. The… | |
| Aplazada | Alta (8.3) | 0.47% | — | SAP S/4hana Cloud Private EditionAISAP S/4hana ON PremiseAI | 13/5/2025 | 17/6/2026 | SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard programs. This is due to lack of input validation and no authorization… | |
| Analizada | Media (5.3) | 0.36% | — | Pribai Privategpt | 10/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the argument allow_origins leads to permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (7.5) | 0.69% | — | Accesspressthemes ArrivalAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpoperations Arrival arrival allows PHP Local File Inclusion.This issue affects Arrival: from n/a through <= 1.4.5. | |
| Analizada | Media (5.3) | 0.45% | — | Profile Private Project Profile Private | 31/3/2025 | 17/6/2026 | Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*. | |
| Aplazada | Alta (8.5) | 0.49% | — | Amentotech Private Limited Wpguppy LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows SQL Injection.This issue affects WPGuppy: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.1) | 0.18% | — | Hotvanrod Adsense Privacy PolicyAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored XSS.This issue affects AdSense Privacy Policy: from n/a through <= 1.1.1. | |
| Analizada | Media (6.1) | 0.35% | — | Pribai Privategpt | 20/3/2025 | 17/6/2026 | An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks. | |
| Modificada | Alta (7.5) | 0.62% | — | Pribai Privategpt | 20/3/2025 | 17/6/2026 | A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled… | |
| Analizada | Alta (7.5) | 0.77% | — | Pribai Privategpt | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing… | |
| Aplazada | Alta (8.5) | 0.33% | — | Aldo Latino Private-contentAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.4. | |
| Aplazada | Alta (7.1) | 0.22% | — | Lcweb PrivatecontentAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5. | |
| Aplazada | Alta (8.3) | 0.30% | — | Lcweb PrivatecontentAI | 15/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5. | |
| Analizada | Crítica (9.1) | 2.1% | — | Nvidia Riva | 11/3/2025 | 17/6/2026 | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service. | |
| Analizada | Crítica (9.8) | 2.0% | — | Nvidia Riva | 11/3/2025 | 17/6/2026 | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Lcweb PrivatecontentAI | 25/2/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5. | |
| Aplazada | Media (5.3) | 0.55% | — | Privateoctopus PicoquicAI | 20/2/2025 | 17/6/2026 | The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). | |
| Aplazada | Media (6.4) | 0.33% | — | Userprivatefiles User Private FilesAI | 19/2/2025 | 17/6/2026 | The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.31% | — | Podamibe Nepal Podamibe Twilio Private CallAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podamibe Nepal Podamibe Twilio Private Call podamibe-twilio-private-call allows Reflected XSS.This issue affects Podamibe Twilio Private Call: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.33% | — | Vikash Srivastava Vstemplate CreatorAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikash Srivastava VSTEMPLATE Creator vstemplate-creator allows Reflected XSS.This issue affects VSTEMPLATE Creator: from n/a through <= 2.0.2. | |
| Modificada | Media (6.1) | 0.58% | 💥 Exploit | Waelhassan Privacy Policy Genius | 31/1/2025 | 17/6/2026 | The Privacy Policy Genius WordPress plugin through 2.0.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7) | 0.39% | — | Rockwellautomation Datamosaix Private CloudAI | 28/1/2025 | 17/6/2026 | A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this… | |
| Aplazada | Media (5.3) | 0.43% | — | Silverplugins Build Private Store FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Build Private Store For Woocommerce: from n/a through <= 1.0. |