Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.62%—Insightsoftware Spark JdbcAI3/4/202517/6/2026
insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
AplazadaMedia (5.3)0.38%—SparklingAI5/3/202517/6/2026
The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.3)0.44%—Sparkshop24/2/202517/6/2026
An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
AnalizadaMedia (6.8)0.90%—Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation4/2/202517/6/2026
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
AplazadaMedia (4.3)0.15%—Sevenspark Contact Form 7 Dynamic Text ExtensionAI31/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Cross Site Request Forgery.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.1.
AnalizadaMedia (5.9)1.6%—Apache HiveApache Spark23/12/202417/6/2026
Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service component…
AplazadaMedia (4.3)0.40%—Sparkle Themes Blogger BuzzAI9/12/202417/6/2026
Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2.
AplazadaMedia (4.3)0.39%—Sparkle Themes ChankheAI9/12/202417/6/2026
Missing Authorization vulnerability in Sparkle Themes Chankhe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chankhe: from n/a through 1.0.5.
AplazadaMedia (6.5)0.29%—Jakub Glos Sparkle Elementor KITAI30/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows DOM-Based XSS.This issue affects Sparkle Elementor Kit: from n/a through <= 2.0.9.
AplazadaMedia (6.5)0.24%—Esparkbiz ESB TestimonialsAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eSparkBiz ESB Testimonials esb-testimonials allows Stored XSS.This issue affects ESB Testimonials: from n/a through <= 1.0.0.
AnalizadaMedia (4.3)0.35%—Sevenspark Contact Form 7 - Dynamic Text Extension5/11/202417/6/2026
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text…
AnalizadaMedia (6.5)0.23%—Sparkshop28/10/202417/6/2026
SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.
AplazadaAlta (8.6)0.59%—Jamespark Analyse UploadsAI16/10/202417/6/2026
Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.
ModificadaAlta (7.5)0.46%—Sparkshop9/10/20245/7/2026
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
AnalizadaCrítica (9.8)0.71%—Sparkshop16/7/202417/6/2026
File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.
AplazadaMedia (5.3)0.43%—SparkshopAI14/7/202417/6/2026
A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of the file /api/Common/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.4)0.18%—Sevenspark Ubermenu22/6/202417/6/2026
The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the ubermenu_delete_all_item_settings and ubermenu_reset_settings functions. This makes it possible for unauthenticated attackers to delete…
ModificadaMedia (6.5)0.50%—Wpneuron Sparkle Demo Importer22/6/202417/6/2026
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AnalizadaAlta (8.6)100%⚠ Explotación activa💥 ExploitCheckpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security28/5/20245/8/2026
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
AplazadaMedia (6.4)0.27%—Sevenspark UbermenuAI21/5/202417/6/2026
The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_mobile_close_button, ubermenu_toggle, ubermenu-search shortcodes in all versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes.…
AplazadaMedia (4.3)0.41%—Sparkle WP EditorialmagAI17/5/202417/6/2026
Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.
AplazadaAlta (7.1)0.35%—Sparkweb Interactive INC Custom Field Bulk EditorAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SparkWeb Interactive, Inc. Custom Field Bulk Editor allows Reflected XSS.This issue affects Custom Field Bulk Editor: from n/a through 1.9.1.
AplazadaMedia (4.3)0.38%—Sparkle WP EducenterAI25/3/202417/6/2026
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
ModificadaMedia (6.1)0.71%—Sparksuite Simplemde17/1/202417/6/2026
A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.8)0.26%—Facebook Meta Spark Studio16/1/202417/6/2026
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
Orbitaley — Vulnerabilidades