Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.21% | — | CubewpAI | 17/1/2026 | 17/6/2026 | The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.25% | — | CubewpAI | 17/1/2026 | 17/6/2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the /cubewp-posts/v1/query-new and /cubewp-posts/v1/query REST API endpoints due to insufficient restrictions on which posts can be included. This makes it… | |
| Aplazada | Alta (7.5) | 0.28% | — | Imran Tauqeer Cubewp Cubewp FrameworkAI | 29/12/2025 | 1/10/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through <= 1.1.27. | |
| Modificada | Media (5.1) | 0.20% | — | Teradek Cube Firmware | 24/12/2025 | 17/6/2026 | Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration interface. | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancorathemes MaxcubeAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PHP Local File Inclusion.This issue affects MaxCube: from n/a through <= 1.3.1. | |
| Analizada | Media (6.1) | 27% | ⚠ Explotación activa | Roundcube Webmail | 18/12/2025 | 17/6/2026 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | |
| Analizada | Alta (7.5) | 0.28% | — | Roundcube Webmail | 18/12/2025 | 17/6/2026 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer. | |
| Analizada | Media (6.5) | 0.31% | — | Metacubex Mihomo | 18/11/2025 | 29/7/2026 | Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file. | |
| Aplazada | Alta (8.2) | 0.37% | — | CubeapmAI | 7/10/2025 | 17/6/2026 | CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bulk endpoint. This endpoint accepts bulk log data without requiring authentication or input validation, allowing remote attackers to perform unauthorized log… | |
| Analizada | Media (6.5) | 0.41% | — | Node-cube | 24/9/2025 | 17/6/2026 | The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the… | |
| Aplazada | Media (6.5) | 0.20% | — | CubewpAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Stored XSS.This issue affects CubeWP: from n/a through <= 1.1.26. | |
| Analizada | Media (6.5) | 0.40% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of… | |
| Analizada | Media (5.4) | 0.28% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input is not properly sanitized before being displayed. An attacker can submit HTML tags inside the review description field. Once the administrator approves the review, the… | |
| Analizada | Media (5.4) | 0.30% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML and that HTML is included verbatim in the email sent to the store admin. By submitting HTML in the Enquiry, the admin receives an email containing that HTML. This indicates user input is not being… | |
| Analizada | Alta (7.1) | 0.20% | — | Cubecart | 22/9/2025 | 17/6/2026 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access… | |
| Aplazada | Media (5.3) | 0.26% | — | Holistic IT Consultancy Coop Workcube ERPAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT, Consultancy Coop. Workcube ERP allows Reflected XSS. This issue affects Workcube ERP: from V12 - V14 before Cognitive. | |
| Aplazada | Crítica (9.2) | 0.60% | — | Itcube CRMAI | 8/9/2025 | 17/6/2026 | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process. | |
| Aplazada | Alta (8.8) | 0.37% | — | Imran Tauqeer Cubewp-frameworkAICubewpAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <= 1.1.24. | |
| Aplazada | Alta (8.5) | 0.27% | — | Ovatheme Cube PortfolioAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ovatheme Cube Portfolio cubeportfolio allows SQL Injection.This issue affects Cube Portfolio: from n/a through <= 1.16.8. | |
| Aplazada | Media (6.5) | 0.19% | — | CubewpAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP cubewp-framework allows DOM-Based XSS.This issue affects CubeWP: from n/a through <= 1.1.23. | |
| Aplazada | Media (4.3) | 0.22% | — | Imran Tauqeer Cubewp FormsAI | 17/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.5. | |
| Analizada | Alta (8.8) | 0.53% | — | Cubewp | 11/6/2025 | 17/6/2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through the update_user_meta() function. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.16% | — | CubewpAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Cross Site Request Forgery.This issue affects CubeWP: from n/a through <= 1.1.29. | |
| Aplazada | Media (4.3) | 0.16% | — | CubepointsAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Lau CubePoints cubepoints allows Cross Site Request Forgery.This issue affects CubePoints: from n/a through <= 3.2.1. | |
| Analizada | Alta (8.8) | 99% | ⚠ Explotación activa | Roundcube WebmailDebian Linux | 2/6/2025 | 17/6/2026 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. |