Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.75% | 💥 PoC | Apache Mina | 1/5/2026 | 17/6/2026 | The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a… | |
| Analizada | Crítica (9.8) | 0.75% | — | Apache Mina | 27/4/2026 | 17/6/2026 | The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.0.0 <= 2.0.27, 2.1.0 <=… | |
| Analizada | Crítica (9.8) | 0.82% | — | Apache Mina | 27/4/2026 | 17/6/2026 | Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted class filter before calling… | |
| Analizada | Alta (8.6) | 0.19% | — | Lizardsystems Terminal Services Manager | 22/4/2026 | 17/6/2026 | Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH… | |
| Analizada | Media (6.4) | 0.16% | — | Redhat WEB Terminal | 8/4/2026 | 24/7/2026 | A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Luminance Studio | 23/3/2026 | 17/6/2026 | Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the… | |
| Analizada | Media (6.9) | 0.19% | — | Lizardsystems Terminal Services Manager | 21/3/2026 | 17/6/2026 | Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing… | |
| Aplazada | Alta (8.1) | 0.43% | — | Speedexam Online Examination SystemAI | 17/3/2026 | 17/6/2026 | An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypass client-side restrictions and invoke this method directly to retrieve the full answer key. The provider states that… | |
| Aplazada | Media (5.3) | 0.26% | — | Wpmudev ForminatorAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Forminator: from n/a through <= 1.50.2. | |
| Aplazada | Alta (8.8) | 0.32% | — | NominasAI | 6/3/2026 | 17/6/2026 | Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username parameter. Attackers can send POST requests to the login/checklogin.php endpoint with crafted UNION-based SQL injection payloads to extract… | |
| Aplazada | Media (4.4) | 0.18% | 💥 PoC | Incsub ForminatorAI | 17/2/2026 | 17/6/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (6.9) | 0.36% | — | Fabian Online Examination System | 8/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. | |
| Aplazada | Media (6.7) | 0.41% | — | ZOC TerminalAI | 5/2/2026 | 17/6/2026 | ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when attempting to create SSH key files. | |
| Aplazada | Media (6.7) | 0.19% | — | ZOC TerminalAI | 5/2/2026 | 17/6/2026 | ZOC Terminal 7.25.5 contains a script processing vulnerability that allows local attackers to crash the application by loading a maliciously crafted REXX script file. Attackers can generate an oversized script with 20,000 repeated characters to trigger an application crash and cause a denial of service. | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Online Examination System | 26/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admin_pic.php. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.53% | — | Fabian Online Examination System | 26/1/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Page. Performing a manipulation of the argument User results in sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Baja (2) | 0.30% | — | Fabian Online Examination System | 26/1/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (4.6) | 0.44% | — | DupterminatorAI | 16/1/2026 | 17/6/2026 | DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text box. Attackers can generate a payload of 8000 repeated characters to trigger the application to stop working on Windows 10. | |
| Aplazada | Media (5.3) | 0.29% | — | Incsub ForminatorAI | 9/1/2026 | 17/6/2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | |
| Analizada | Crítica (10) | 2.1% | — | Gongrzhe Terminal-controller-mcp | 7/1/2026 | 17/6/2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input. | |
| Aplazada | Media (6.5) | 0.19% | — | Thinkupthemes MinamazeAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thinkupthemes Minamaze minamaze allows Stored XSS.This issue affects Minamaze: from n/a through <= 1.10.1. | |
| Aplazada | Media (5.1) | 0.21% | — | AVE DominaplusAI | 24/12/2025 | 17/6/2026 | AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions. | |
| Aplazada | Media (6.5) | 0.12% | — | Identity Agent FOR Terminal ServicesAI | 22/12/2025 | 17/6/2026 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files. | |
| Modificada | Media (5.5) | 0.39% | — | Campcodes Advanced Online Examination System | 14/12/2025 | 28/9/2026 | A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Analizada | Media (6.9) | 0.21% | — | Waveterm Wave Terminal | 12/12/2025 | 17/6/2026 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. |