Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

21.644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.26%—Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI13/8/202614/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress…
AplazadaAlta (7.2)0.27%—Gutenverse CompanionAI13/8/202614/8/2026
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
AplazadaMedia (6.5)0.22%—FluentcommunityAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
AplazadaAlta (7.5)0.35%—Clink Bitcoin Lightning Payment GatewayAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
AplazadaAlta (8.1)0.37%—Miniorange Saml SP Single Sign ONAI13/8/202614/8/2026
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
AplazadaCrítica (9.8)0.48%—Miniorange OTP VerificationAI13/8/202614/8/2026
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
AplazadaMedia (6)0.25%—Teltonika-networks RutosAI13/8/20268/9/2026
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected service could trigger a heap-based buffer overflow, resulting in a denial of service.
AplazadaMedia (6.9)0.29%—Teltonika-networks RutosAITeltonika-networks TswosAI13/8/20268/9/2026
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
AplazadaAlta (7.5)0.41%💥 PoCIqonic KivicareAI13/8/202626/8/2026
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
AplazadaMedia (5.1)0.31%—National Institute OF Information AND Communications Technology VoicetraAI13/8/202628/8/2026
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display…
AnalizadaCrítica (9.9)0.59%—Canonical LXD12/8/202611/9/2026
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by…
AnalizadaAlta (8.5)0.35%—Canonical LXD12/8/202611/9/2026
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine /…
AnalizadaCrítica (9.9)0.54%—Canonical LXD12/8/202611/9/2026
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the…
AnalizadaCrítica (9.9)0.59%—Canonical LXD12/8/202611/9/2026
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across…
AnalizadaCrítica (9.9)0.69%—Canonical LXD12/8/202611/9/2026
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can…
AnalizadaCrítica (9.9)0.34%—Canonical LXD12/8/202611/9/2026
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is…
AnalizadaCrítica (9.9)0.44%—Canonical LXD12/8/202611/9/2026
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions.…
AnalizadaMedia (4.3)0.35%—Canonical LXD12/8/202611/9/2026
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an…
AnalizadaCrítica (9.9)0.88%—Canonical LXD12/8/202611/9/2026
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by…
AnalizadaCrítica (9.9)0.59%—Canonical LXD12/8/20263/9/2026
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive…
AnalizadaCrítica (9.9)0.54%—Canonical LXD12/8/202611/9/2026
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target:…
AplazadaMedia (6.3)0.17%—Ministry OF Justice Uyap Document EditorAI12/8/202626/8/2026
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.
AplazadaAlta (8.8)0.43%—Iqonic KivicareAI12/8/202626/8/2026
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.
AplazadaMedia (4.3)0.25%—Iqonic KivicareAI12/8/202626/8/2026
The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices and appointment details.
AplazadaAlta (8.7)0.55%—Phoenixcontact Plcnext EngineerAI12/8/202629/9/2026
Una vulnerabilidad de denegación de servicio no autenticada en la interfaz de comunicación PLCnext Engineer del dispositivo permite a un atacante remoto interrumpir el acceso a través de la aplicación cliente. La explotación exitosa impide la comunicación hasta que el servicio PLCnext se reinicie manualmente.