Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 30/4/2026 | 17/6/2026 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's… | |
| Analizada | Alta (7.5) | 0.54% | — | Miyagawa Starman | 29/4/2026 | 24/7/2026 | Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could… | |
| Analizada | Media (6.3) | 0.14% | — | Siemens Simcenter 3DSiemens Simcenter FemapSiemens Simcenter Star-ccm+ ViewerSiemens Software Center+3 | 14/4/2026 | 29/6/2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0… | |
| Aplazada | Media (6.5) | 0.21% | — | Rustaurius Five Star Restaurant ReservationsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9. | |
| Aplazada | Baja (2.3) | 0.32% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack… | |
| Aplazada | Media (5.3) | 0.34% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.36% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely. | |
| Analizada | Alta (7.5) | 0.52% | — | Wgstart Wgcloud | 19/3/2026 | 17/6/2026 | There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server. | |
| Analizada | Alta (7.5) | 0.40% | — | Wgstart Wgcloud | 19/3/2026 | 17/6/2026 | The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations. | |
| Analizada | Crítica (9.8) | 0.92% | — | Wgstart Wgcloud | 19/3/2026 | 17/6/2026 | An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function | |
| Analizada | Media (5.8) | 0.42% | — | Amazon Bedrock Agentcore Starter Toolkit | 16/3/2026 | 17/6/2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who… | |
| Aplazada | Media (6.5) | 0.22% | — | Immonex KickstartAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in immonex immonex Kickstart immonex-kickstart allows Stored XSS.This issue affects immonex Kickstart: from n/a through <= 1.13.0. | |
| Aplazada | Alta (8.1) | 0.58% | — | Themeref StargazeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Stargaze stargaze allows PHP Local File Inclusion.This issue affects Stargaze: from n/a through <= 1.5. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods StartoAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through < 2.2.5. | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | Supremainc Biostar 2AI | 4/3/2026 | 17/6/2026 | Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise. | |
| Aplazada | Alta (8.1) | 0.53% | — | Qodeinteractive FivestarAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes FiveStar fivestar allows PHP Local File Inclusion.This issue affects FiveStar: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.34% | — | Starfish Review Generation AND MarketingAI | 13/2/2026 | 17/6/2026 | The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, 3.1.19. This makes it possible… | |
| Analizada | Media (6.5) | 0.52% | — | Litestar | 9/2/2026 | 17/6/2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileStore is used as response-cache backend, an unauthenticated remote attacker can… | |
| Analizada | Media (6.5) | 0.42% | — | Litestar | 9/2/2026 | 17/6/2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker… | |
| Analizada | Media (6.5) | 0.48% | — | Litestar | 9/2/2026 | 17/6/2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used with fullmatch() for validation. Because metacharacters are not escaped, a malicious origin can match unexpectedly. The… | |
| Aplazada | Alta (8.5) | 0.15% | — | HP JumpstartAI | 6/2/2026 | 17/6/2026 | JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions. | |
| Aplazada | Media (4.3) | 0.15% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/2/2026 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks. | |
| Aplazada | Alta (8.6) | 0.19% | — | Simple Startup ManagerAI | 30/1/2026 | 17/6/2026 | Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory through the 'File' input parameter. Attackers can craft a malicious payload with 268 bytes to trigger code execution, bypassing DEP and overwriting memory addresses to launch… | |
| Aplazada | Alta (7.1) | 0.45% | — | Johnsoncontrols Istar Configuration UtilityAI | 28/1/2026 | 17/6/2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool. | |
| Aplazada | Media (4.3) | 0.18% | — | Star Review ManagerAI | 24/1/2026 | 17/6/2026 | The Star Review Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's CSS settings via a forged request granted they… |