Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.23% | — | Smartcom Bulgaria AD Smartcom Ralink CPEAISmartcom Bulgaria AD Sam-4g1g-tt-w-vcAISmartcom Bulgaria AD Sam-4f1f-tt-w-a1AI | 6/2/2025 | 5/7/2026 | An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers. | |
| Analizada | Media (6.5) | 0.56% | — | Vmware Aria OperationsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. | |
| Analizada | Media (4.8) | 0.40% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration. | |
| Analizada | Media (5.4) | 0.33% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. | |
| Analizada | Crítica (9) | 0.67% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user. | |
| Analizada | Alta (7.7) | 0.68% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs | |
| Analizada | Media (4.3) | 0.19% | — | Variation Swatches FOR Woocommerce Project Variation Swatches FOR Woocommerce | 23/1/2025 | 17/6/2026 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the… | |
| Aplazada | Media (4.3) | 0.26% | — | Vmware Aria AutomationAI | 8/1/2025 | 17/6/2026 | VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network. | |
| Aplazada | Crítica (9.1) | 18% | 💥 PoC | LibrarianAI | 7/1/2025 | 17/6/2026 | I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php | |
| Analizada | Media (5.4) | 0.20% | — | Themehunk Variation Swatches | 9/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation Swatches: from n/a through 1.2.7. | |
| Analizada | Media (4.8) | 0.31% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (5.4) | 0.40% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (6.4) | 0.44% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.29% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.18% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations. | |
| Aplazada | Alta (7.5) | 0.63% | — | Wpopal Opal WOO Custom Product VariationAI | 20/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-custom-product-variation allows Path Traversal.This issue affects Opal Woo Custom Product Variation: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Mariandz TeleadminAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mariandz TeleAdmin teleadmin allows Reflected XSS.This issue affects TeleAdmin: from n/a through <= 1.0.0. | |
| Analizada | Baja (2.3) | 0.45% | — | Mariazevedo88 Travels-java-api | 6/11/2024 | 17/6/2026 | A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the component JWT Secret… | |
| Aplazada | Media (4.6) | 0.29% | — | LibrarianAI | 30/10/2024 | 17/6/2026 | I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to be executed with the application context. An attacker can… | |
| Modificada | Media (6.1) | 0.29% | — | Marianheddesheimer Extra Privacy FOR Elementor | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marian Heddesheimer Extra Privacy for Elementor extra-privacy-for-elementor allows Reflected XSS.This issue affects Extra Privacy for Elementor: from n/a through <= 0.1.3. | |
| Analizada | Media (5.7) | 1.3% | 💥 PoC | Mariadb | 17/10/2024 | 17/6/2026 | An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |
| Analizada | Media (5.6) | 0.73% | 💥 PoC | Mariadb | 17/10/2024 | 17/6/2026 | Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |
| Analizada | Crítica (9.8) | 2.2% | — | Mariadb | 17/10/2024 | 17/6/2026 | MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |
| Aplazada | Media (4.3) | 0.18% | — | Razon Komar PAL Linked Variation FOR WoocommerceAI | 17/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce linked-variation-for-woocommerce allows Cross Site Request Forgery.This issue affects Linked Variation for WooCommerce: from n/a through <= 1.0.5. | |
| Analizada | Alta (8.6) | 0.60% | — | Scilico I, Librarian | 12/8/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component. |