Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.30% | — | Themegoods Grand Conference | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4. | |
| Aplazada | Alta (8.5) | 0.26% | — | Quadlayers Perfect Brands FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocommerce-brands allows SQL Injection.This issue affects Perfect Brands for WooCommerce: from n/a through <= 3.6.2. | |
| Aplazada | Media (5.4) | 0.27% | — | Brandexponents Oshine CoreAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in brandexponents Oshine Core oshine-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oshine Core: from n/a through <= 1.5.5. | |
| Aplazada | Baja (1.2) | 0.19% | — | GrandnodeAI | 10/9/2025 | 17/6/2026 | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched remotely. The attack requires a high… | |
| Aplazada | Baja (3.2) | 0.15% | — | Intel RdrandAIAMD SEV SNPAI | 5/9/2025 | 17/6/2026 | Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests. | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 1/9/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container. | |
| Modificada | Alta (7.6) | 0.30% | — | Grandstream Gxp1628 Firmware | 29/7/2025 | 5/7/2026 | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files. | |
| Modificada | Media (6.5) | 0.30% | — | Grandstream Ucm6510 Firmware | 29/7/2025 | 5/7/2026 | An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi. | |
| Modificada | Media (6.5) | 0.27% | — | Grandstream Ucm6510 Firmware | 29/7/2025 | 5/7/2026 | Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force attack. | |
| Aplazada | Media (6.4) | 0.27% | — | BrandfolderAI | 16/7/2025 | 17/6/2026 | The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 5.0.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (4) | 0.20% | — | Dracoon Branding ServiceAI | 15/7/2025 | 17/6/2026 | DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users could inject HTML code… | |
| Aplazada | Media (4.3) | 0.15% | — | Imw3 MY WP BrandAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in imw3 My Wp Brand my-wp-brand allows Cross Site Request Forgery.This issue affects My Wp Brand: from n/a through <= 1.1.3. | |
| Aplazada | Media (5.9) | 0.26% | — | Robert Peake Better Random RedirectAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Peake Better Random Redirect better-random-redirect allows Stored XSS.This issue affects Better Random Redirect: from n/a through <= 1.3.20. | |
| Aplazada | Media (4.3) | 0.26% | — | Grandplugins Image Sizes ControllerAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a… | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Grandprix | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6. | |
| Modificada | Crítica (9.8) | 0.59% | — | Themegoods Grand Tour | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5.6. | |
| Analizada | Media (4.3) | 0.44% | — | Hot-themes HOT Random Image | 22/5/2025 | 17/6/2026 | The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrary images with allowed extensions, outside of the originally… | |
| Analizada | Media (5.4) | 0.28% | — | Hot-themes HOT Random Image | 22/5/2025 | 17/6/2026 | The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Modificada | Crítica (9.8) | 0.46% | — | Themegoods Grand Conference | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.This issue affects Grand Conference: from n/a through <= 5.3. | |
| Modificada | Alta (8.2) | 0.31% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Crítica (9.8) | 0.46% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Crítica (9.8) | 0.55% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Path Traversal.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Media (5.3) | 0.26% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Modificada | Media (4.3) | 0.14% | — | Themegoods Grand Restaurant | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request Forgery.This issue affects Grand Restaurant: from n/a through <= 7.0. | |
| Analizada | Media (5.4) | 0.30% | — | Grandplugins Avif Uploader | 15/5/2025 | 17/6/2026 | The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. |