Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials. | |
| Aplazada | Alta (8.1) | 0.58% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink creation. | |
| Aplazada | Crítica (9.9) | 0.74% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service. | |
| Aplazada | Alta (7.5) | 0.56% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data. | |
| Aplazada | Alta (8.8) | 0.74% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service. | |
| Aplazada | Alta (8.8) | 0.51% | — | NetatalkAIMysqlAI | 21/5/2026 | 23/7/2026 | An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service. | |
| Analizada | Alta (8.3) | 0.66% | — | Kovai Biztalk360 | 3/4/2026 | 24/7/2026 | An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal. | |
| Modificada | Alta (8.8) | 0.46% | — | Kovai Biztalk360 | 3/4/2026 | 24/7/2026 | An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server. | |
| Modificada | Media (6.8) | 0.88% | — | Kovai Biztalk360 | 3/4/2026 | 24/7/2026 | An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal. | |
| Analizada | Media (4.7) | 0.21% | — | Cleantalk Anti-spam | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Cross-Site Scripting (XSS).This issue affects Anti-Spam by CleanTalk: from 0.0.0 before 9.7.0. | |
| Analizada | Media (6.8) | 0.17% | — | Nsasoft Spotpaltalk | 21/3/2026 | 17/6/2026 | SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK… | |
| Aplazada | Media (4.4) | 0.21% | — | TalkjsAI | 19/2/2026 | 17/6/2026 | The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Crítica (9.8) | 1.2% | — | CleantalkAI | 15/2/2026 | 17/6/2026 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for… | |
| Aplazada | Media (4.6) | 0.30% | — | Gtalk Password FinderAI | 11/2/2026 | 17/6/2026 | GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash. | |
| Aplazada | Alta (8.5) | 0.21% | — | Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI | 5/2/2026 | 17/6/2026 | Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject… | |
| Aplazada | Alta (7.2) | 0.31% | — | Cleantalk Login Security Firewall Malware RemovalAI | 9/12/2025 | 17/6/2026 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (4.3) | 0.25% | — | Nextcloud Talk | 5/12/2025 | 17/6/2026 | Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and 21.1.2. | |
| Aplazada | Media (6.4) | 0.18% | — | Brighttalk Wordpress ShortcodeAI | 21/11/2025 | 17/6/2026 | The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attribute in the brighttalk-time shortcode in all versions up to, and including, 2.4.0. This is due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.3) | 0.24% | — | UI Unifi Talk TouchAIUI Unifi Talk Touch MAXAIUI Unifi Talk G3AI | 31/10/2025 | 17/6/2026 | A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Products: UniFi Talk Touch… | |
| Aplazada | Alta (7.5) | 0.30% | — | TalktalkAI | 30/10/2025 | 17/6/2026 | TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying request parameters, attackers may obtain sensitive user information (such as device identifiers and birthdays) and access private group information, including join credentials. Successful exploitation… | |
| Analizada | Alta (8.5) | 0.18% | — | Rockwellautomation Factorytalk Linx | 14/10/2025 | 17/6/2026 | A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching… | |
| Analizada | Alta (8.5) | 0.18% | — | Rockwellautomation Factorytalk Linx | 14/10/2025 | 17/6/2026 | A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full… | |
| Aplazada | Alta (8.7) | 0.46% | — | Rockwellautomation Factorytalk ViewpointAI | 14/10/2025 | 17/6/2026 | A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service. | |
| Analizada | Alta (8.7) | 0.61% | — | Rockwellautomation Factorytalk View | 14/10/2025 | 17/6/2026 | A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted. | |
| Analizada | Alta (7) | 0.39% | — | Rockwellautomation Factorytalk View | 14/10/2025 | 17/6/2026 | An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more. |