Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.40% | — | Calibre-ebook Calibre | 6/2/2026 | 17/6/2026 | calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which… | |
| Modificada | Alta (7.5) | 2.6% | — | Facebook React | 26/1/2026 | 15/7/2026 | Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to… | |
| Aplazada | Alta (8.7) | 0.70% | — | PhreebooksAI | 23/1/2026 | 17/6/2026 | PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server. | |
| Analizada | Media (4.8) | 0.22% | — | Facebook Pixel Project Facebook Pixel | 14/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Facebook Pixel facebook_pixel allows Stored XSS.This issue affects Facebook Pixel: from 7.X-1.0 through 7.X-1.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Awethemes AwebookingAI | 5/1/2026 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embedded Sensitive Data.This issue affects AweBooking: from n/a through <= 3.2.26. | |
| Analizada | Media (5.5) | 0.39% | — | Facebook-riares Online PET Shop Management System | 14/12/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/update_cnp.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Media (5.5) | 0.39% | — | Facebook-riares Online PET Shop Management System | 13/12/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could… | |
| Analizada | Media (5.5) | 0.39% | — | Facebook-riares Online PET Shop Management System | 13/12/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of the file /pet1/available.php. Such manipulation of the argument Name leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Modificada | Alta (7.5) | 20% | — | Facebook ReactVercel Next.js | 12/12/2025 | 17/6/2026 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function… | |
| Modificada | Alta (7.5) | 67% | 💥 Exploit | Facebook ReactVercel Next.js | 11/12/2025 | 17/6/2026 | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes… | |
| Analizada | Media (5.3) | 64% | 💥 PoC | Vercel Next.jsFacebook React | 11/12/2025 | 17/6/2026 | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent… | |
| Aplazada | Media (5.3) | 0.21% | — | Themetechmount TruebookerAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.3) | 0.13% | — | JK Social Photo Fetcher Facebook Photo FetcherAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in JK Social Photo Fetcher facebook-photo-fetcher allows Cross Site Request Forgery.This issue affects Social Photo Fetcher: from n/a through <= 3.0.4. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Facebook ReactVercel Next.js | 3/12/2025 | 4/8/2026 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP… | |
| Analizada | Media (5.3) | 0.29% | — | Facebook Proxygen | 2/12/2025 | 17/6/2026 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually causes the process to… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 24/11/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 18/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Aplazada | Crítica (9.3) | 0.18% | — | Calibre-ebook CalibreAI | 8/11/2025 | 17/6/2026 | calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution.… | |
| Aplazada | Media (5.3) | 0.22% | — | Facebook FOR WoocommerceAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Facebook for WooCommerce: from n/a through <= 3.5.7. | |
| Aplazada | Alta (8.7) | 0.44% | — | Plone VoltoAIFacebook ReactAI | 2/10/2025 | 17/6/2026 | Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue… | |
| Aplazada | Media (6.5) | 0.21% | — | Nextendweb Nextend Facebook ConnectAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nextendweb Nextend Facebook Connect nextend-facebook-connect allows Stored XSS.This issue affects Nextend Facebook Connect : from n/a through <= 3.1.19. | |
| Analizada | Baja (2) | 0.28% | — | Facebook-riares Online Petshop Management System | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to launch the attack… | |
| Analizada | Baja (2) | 0.28% | — | Facebook-riares Online Petshop Management System | 18/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.34% | — | Facebook-julykringcadayona Student Information System | 17/9/2025 | 25/9/2026 | A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of the argument level_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (6.5) | 0.32% | — | Wpsimplebookingcalendar WP Simple Booking CalendarAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calendar: from n/a through <= 2.0.13. |