Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
293.946 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | WP Media Rocket Rocket Lazy LoadAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy Load: from n/a through 2.4.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Wpchill Modula Image GalleryAI | 7/10/2026 | 7/10/2026 | Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes Prime SliderAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Wedevs Happy Addons FOR ElementorAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.50.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Expresstechsoftsolutions Quiz AND Survey MasterAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7. | |
| Aplazada | Media (4.3) | 0.21% | — | Arraytics BookticsAI | 7/10/2026 | 7/10/2026 | Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27. | |
| Pendiente de análisis | Media (6.1) | 0.30% | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials. | |
| Aplazada | Alta (7.1) | 0.29% | — | Satel-iberia Sennet Datalogger Serie 200AI | 7/10/2026 | 7/10/2026 | Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path… | |
| Pendiente de análisis | Alta (8.3) | 0.37% | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Veeam Agent FOR Microsoft WindowsAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | |
| Pendiente de análisis | Alta (8.1) | 0.21% | — | Zephyrproject ZephyrAI | 7/10/2026 | 7/10/2026 | ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter… | |
| Pendiente de análisis | Alta (8.8) | 0.31% | — | Zephyrproject ZephyrAI | 7/10/2026 | 7/10/2026 | The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out,… | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | — | Ordasoft Simple MembershipAI | 7/10/2026 | 7/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter,… | |
| Pendiente de análisis | Media (6.9) | 0.24% | — | Ordasoft Touch SliderAI | 7/10/2026 | 7/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a… | |
| Pendiente de análisis | Crítica (9.4) | 0.36% | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server. | |
| Pendiente de análisis | Media (4.8) | 0.34% | — | Veeam Backup Enterprise ManagerAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link. | |
| Pendiente de análisis | Media (4.1) | 0.12% | — | Veeam Agent FOR Microsoft WindowsAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | |
| Aplazada | Media (4.1) | 0.18% | — | Blubrry PowerpressAI | 7/10/2026 | 7/10/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services. | |
| Aplazada | Media (4.3) | 0.18% | — | Userprivatefiles User Private FilesAI | 7/10/2026 | 7/10/2026 | The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators. | |
| Aplazada | Alta (8.8) | 0.38% | — | String LocatorAI | 7/10/2026 | 7/10/2026 | The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a… | |
| Aplazada | Media (5.4) | 0.16% | — | MetformAI | 7/10/2026 | 7/10/2026 | The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | |
| Aplazada | Media (5.3) | 0.23% | — | Themewinter WpcafeAI | 7/10/2026 | 7/10/2026 | The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication. | |
| Aplazada | Media (5.3) | 0.19% | — | Hoosoft Magee ShortcodesAI | 7/10/2026 | 7/10/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay). | |
| Aplazada | Alta (7.1) | 0.16% | — | Hoosoft Magee ShortcodesAI | 7/10/2026 | 7/10/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting. | |
| Aplazada | Baja (2.7) | 0.17% | — | CP Media PlayerAI | 7/10/2026 | 7/10/2026 | The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that… |