Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Rohil Contact Form 7 Hide Success MessageAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Rohil Contact Form – 7 : Hide Success Message contact-form-7-hide-success-message allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contact Form – 7 : Hide Success Message: from n/a through <= 1.1.4. | |
| Analizada | Media (5.5) | 0.10% | — | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort. | |
| Analizada | Media (5.3) | 0.13% | — | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues. | |
| Analizada | Crítica (9.8) | 0.32% | — | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary. | |
| Analizada | Media (4) | 0.55% | ⚠ Explotación activa | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025. | |
| Analizada | Media (5.3) | 11% | ⚠ Explotación activa | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025. | |
| Analizada | Alta (7.5) | 0.25% | — | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers. | |
| Analizada | Alta (7.5) | 0.26% | — | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential. | |
| Aplazada | Alta (7.1) | 0.22% | — | Shanebp BP Messages ToolAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Messages Tool bp-messages-tool allows Reflected XSS.This issue affects BP Messages Tool: from n/a through <= 2.2. | |
| Analizada | Alta (7.5) | 0.39% | — | Smarsh Telemessage | 8/5/2025 | 17/6/2026 | The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password. | |
| Analizada | Media (4.9) | 0.45% | ⚠ Explotación activa | Telemessage Text Message Archiver | 8/5/2025 | 17/6/2026 | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild… | |
| Modificada | Alta (7.2) | 0.39% | — | Kofimokome Message Filter FOR Contact Form 7 | 22/4/2025 | 24/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a through 1.6.3.2. | |
| Aplazada | Media (5.3) | 0.40% | — | Accept Sagepay Payments Using Contact Form 7AI | 8/4/2025 | 17/6/2026 | The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in… | |
| Aplazada | Media (4.3) | 0.19% | — | Powerfulwp Gift Message FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in powerfulwp Gift Message for WooCommerce gift-message-for-woocommerce allows Cross Site Request Forgery.This issue affects Gift Message for WooCommerce: from n/a through <= 1.7.8. | |
| Aplazada | Media (5.9) | 0.37% | — | Gopiplus Message TickerAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Message ticker message-ticker allows Stored XSS.This issue affects Message ticker: from n/a through <= 9.3. | |
| Aplazada | Media (5.9) | 0.26% | — | Amazon Sagemaker Python SDKAI | 20/3/2025 | 17/6/2026 | A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause… | |
| Aplazada | Crítica (9.8) | 0.44% | — | ViidureAISage X3AI | 18/3/2025 | 17/6/2026 | An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Sage X3AI | 18/3/2025 | 17/6/2026 | An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices. | |
| Analizada | Media (4.8) | 0.27% | — | Gallagherwebsitedesign Coronavirus (covid-19) Notice Message | 11/3/2025 | 17/6/2026 | The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (8.9) | 0.63% | — | Intlify Message ResolverAIIntlify VUE I18n CoreAIVuejs VUE I18nAI | 7/3/2025 | 17/6/2026 | Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype… | |
| Aplazada | Alta (7.1) | 0.36% | — | Sage 200 SpainAI | 7/3/2025 | 17/6/2026 | SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker. | |
| Aplazada | Alta (7.1) | 0.32% | — | Sage 200 SpainAI | 7/3/2025 | 17/6/2026 | Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials. | |
| Analizada | Media (6.5) | 0.28% | — | Wordplus Better Messages | 1/3/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Analizada | Alta (7.5) | 0.50% | — | Wordplus Better Messages | 1/3/2025 | 17/6/2026 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract… | |
| Analizada | Alta (8.1) | 0.73% | 💥 PoC | Sagedpw Sage DPW | 18/2/2025 | 17/6/2026 | Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the option to do so in the… |