Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.62% | — | Insightsoftware Spark JdbcAI | 3/4/2025 | 17/6/2026 | insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution. | |
| Aplazada | Media (5.3) | 0.38% | — | SparklingAI | 5/3/2025 | 17/6/2026 | The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (5.3) | 0.44% | — | Sparkshop | 24/2/2025 | 17/6/2026 | An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. | |
| Analizada | Media (6.8) | 0.90% | — | Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation | 4/2/2025 | 17/6/2026 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Aplazada | Media (4.3) | 0.15% | — | Sevenspark Contact Form 7 Dynamic Text ExtensionAI | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Cross Site Request Forgery.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.1. | |
| Analizada | Media (5.9) | 1.6% | — | Apache HiveApache Spark | 23/12/2024 | 17/6/2026 | Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service component… | |
| Aplazada | Media (4.3) | 0.40% | — | Sparkle Themes Blogger BuzzAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2. | |
| Aplazada | Media (4.3) | 0.39% | — | Sparkle Themes ChankheAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle Themes Chankhe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chankhe: from n/a through 1.0.5. | |
| Aplazada | Media (6.5) | 0.29% | — | Jakub Glos Sparkle Elementor KITAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows DOM-Based XSS.This issue affects Sparkle Elementor Kit: from n/a through <= 2.0.9. | |
| Aplazada | Media (6.5) | 0.24% | — | Esparkbiz ESB TestimonialsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eSparkBiz ESB Testimonials esb-testimonials allows Stored XSS.This issue affects ESB Testimonials: from n/a through <= 1.0.0. | |
| Analizada | Media (4.3) | 0.35% | — | Sevenspark Contact Form 7 - Dynamic Text Extension | 5/11/2024 | 17/6/2026 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text… | |
| Analizada | Media (6.5) | 0.23% | — | Sparkshop | 28/10/2024 | 17/6/2026 | SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server. | |
| Aplazada | Alta (8.6) | 0.59% | — | Jamespark Analyse UploadsAI | 16/10/2024 | 17/6/2026 | Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5. | |
| Modificada | Alta (7.5) | 0.46% | — | Sparkshop | 9/10/2024 | 5/7/2026 | A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. | |
| Analizada | Crítica (9.8) | 0.71% | — | Sparkshop | 16/7/2024 | 17/6/2026 | File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component. | |
| Aplazada | Media (5.3) | 0.43% | — | SparkshopAI | 14/7/2024 | 17/6/2026 | A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of the file /api/Common/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.18% | — | Sevenspark Ubermenu | 22/6/2024 | 17/6/2026 | The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or incorrect nonce validation on the ubermenu_delete_all_item_settings and ubermenu_reset_settings functions. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Media (6.5) | 0.50% | — | Wpneuron Sparkle Demo Importer | 22/6/2024 | 17/6/2026 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa💥 Exploit | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Aplazada | Media (6.4) | 0.27% | — | Sevenspark UbermenuAI | 21/5/2024 | 17/6/2026 | The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_mobile_close_button, ubermenu_toggle, ubermenu-search shortcodes in all versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (4.3) | 0.41% | — | Sparkle WP EditorialmagAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9. | |
| Aplazada | Alta (7.1) | 0.35% | — | Sparkweb Interactive INC Custom Field Bulk EditorAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SparkWeb Interactive, Inc. Custom Field Bulk Editor allows Reflected XSS.This issue affects Custom Field Bulk Editor: from n/a through 1.9.1. | |
| Aplazada | Media (4.3) | 0.38% | — | Sparkle WP EducenterAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5. | |
| Modificada | Media (6.1) | 0.71% | — | Sparksuite Simplemde | 17/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.8) | 0.26% | — | Facebook Meta Spark Studio | 16/1/2024 | 17/6/2026 | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application. |