Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

293.946 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—WP Media Rocket Rocket Lazy LoadAI7/10/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy Load: from n/a through 2.4.0.
AplazadaMedia (5.3)0.25%—Wpchill Modula Image GalleryAI7/10/20267/10/2026
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11.
AplazadaMedia (6.5)0.21%—Bdthemes Prime SliderAI7/10/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2.
AplazadaMedia (6.5)0.22%—Wedevs Happy Addons FOR ElementorAI7/10/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.50.0.
AplazadaMedia (6.5)0.22%—Expresstechsoftsolutions Quiz AND Survey MasterAI7/10/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7.
AplazadaMedia (4.3)0.21%—Arraytics BookticsAI7/10/20267/10/2026
Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27.
Pendiente de análisisMedia (6.1)0.30%—Veeam Backup AND ReplicationAI7/10/20267/10/2026
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.
AplazadaAlta (7.1)0.29%—Satel-iberia Sennet Datalogger Serie 200AI7/10/20267/10/2026
Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path…
Pendiente de análisisAlta (8.3)0.37%—Veeam Backup AND ReplicationAI7/10/20267/10/2026
This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.
Pendiente de análisisMedia (6.8)0.10%—Veeam Agent FOR Microsoft WindowsAI7/10/20267/10/2026
This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.
Pendiente de análisisAlta (8.1)0.21%—Zephyrproject ZephyrAI7/10/20267/10/2026
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter…
Pendiente de análisisAlta (8.8)0.31%—Zephyrproject ZephyrAI7/10/20267/10/2026
The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out,…
Pendiente de análisisCrítica (9.3)0.28%—Ordasoft Simple MembershipAI7/10/20267/10/2026
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter,…
Pendiente de análisisMedia (6.9)0.24%—Ordasoft Touch SliderAI7/10/20267/10/2026
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a…
Pendiente de análisisCrítica (9.4)0.36%—Veeam Backup AND ReplicationAI7/10/20267/10/2026
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.
Pendiente de análisisMedia (4.8)0.34%—Veeam Backup Enterprise ManagerAI7/10/20267/10/2026
This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.
Pendiente de análisisMedia (4.1)0.12%—Veeam Agent FOR Microsoft WindowsAI7/10/20267/10/2026
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
AplazadaMedia (4.1)0.18%—Blubrry PowerpressAI7/10/20267/10/2026
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
AplazadaMedia (4.3)0.18%—Userprivatefiles User Private FilesAI7/10/20267/10/2026
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
AplazadaAlta (8.8)0.38%—String LocatorAI7/10/20267/10/2026
The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a…
AplazadaMedia (5.4)0.16%—MetformAI7/10/20267/10/2026
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
AplazadaMedia (5.3)0.23%—Themewinter WpcafeAI7/10/20267/10/2026
The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
AplazadaMedia (5.3)0.19%—Hoosoft Magee ShortcodesAI7/10/20267/10/2026
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
AplazadaAlta (7.1)0.16%—Hoosoft Magee ShortcodesAI7/10/20267/10/2026
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
AplazadaBaja (2.7)0.17%—CP Media PlayerAI7/10/20267/10/2026
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that…