Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.7% | 💥 Exploit | Talkative IRCAI | 16/9/2025 | 1/10/2026 | Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execution in the context… | |
| Analizada | Alta (7.3) | 0.55% | — | Rockwellautomation Factorytalk Optix | 9/9/2025 | 17/6/2026 | A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution. | |
| Analizada | Alta (8.7) | 0.37% | — | Rockwellautomation Factorytalk Activation Manager | 9/9/2025 | 17/6/2026 | A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise. | |
| Analizada | Alta (8.7) | 0.29% | — | Rockwellautomation Factorytalk Analytics Logixai | 9/9/2025 | 1/10/2026 | An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data. | |
| Aplazada | Media (6.5) | 0.22% | — | Codemstory Mshop-naver-talktalkAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemstory 코드엠샵 소셜톡 mshop-naver-talktalk allows Stored XSS.This issue affects 코드엠샵 소셜톡: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.17% | — | Rumbletalk Live Group ChatAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Stored XSS.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.3.5. | |
| Analizada | Alta (8.4) | 0.50% | — | Rockwellautomation Factorytalk Linx | 14/8/2025 | 17/6/2026 | A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers. | |
| Aplazada | Alta (8.5) | 0.14% | — | Rockwellautomation Factorytalk ViewpointAI | 14/8/2025 | 17/6/2026 | A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command prompt, enabling full privilege… | |
| Aplazada | Media (5.9) | 0.26% | — | Rodrigo Bastos Hand TalkAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rodrigo Bastos Hand Talk handtalk allows Stored XSS.This issue affects Hand Talk: from n/a through <= 6.1. | |
| Analizada | Media (5.9) | 0.23% | — | Jenkins Dingtalk | 14/5/2025 | 17/6/2026 | Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks. | |
| Aplazada | Alta (7.1) | 0.21% | — | Sodena Frescochat Live ChatAISodena Flexytalk-widgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sodena FrescoChat Live Chat flexytalk-widget allows Stored XSS.This issue affects FrescoChat Live Chat: from n/a through <= 3.2.6. | |
| Analizada | Crítica (9.8) | 1.6% | — | Cleantalk Security & Malware Scan | 12/2/2025 | 17/6/2026 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for… | |
| Analizada | Alta (7) | 0.38% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user. | |
| Analizada | Alta (7.3) | 0.33% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages. | |
| Analizada | Crítica (9.3) | 0.37% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application. | |
| Aplazada | Media (5.4) | 0.81% | 💥 PoC | Rumbletalk Live Group ChatAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.2.5. | |
| Aplazada | Alta (8.8) | 0.70% | — | Cleantalk Spam Protection Antispam FirewallAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10. | |
| Aplazada | Media (6.4) | 0.26% | — | Codemshop Social TalkAI | 7/12/2024 | 17/6/2026 | The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'msntt_add_plus_talk' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.5) | 3.7% | — | Cleantalk Spam Protection, Antispam, Firewall | 26/11/2024 | 17/6/2026 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.55% | — | Cleantalk Security Malware ScanAI | 26/11/2024 | 17/6/2026 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as insufficient input sanitization and validation. This makes it… | |
| Analizada | Alta (7.5) | 15% | 💥 PoC | Cleantalk Anti-spam | 26/11/2024 | 17/6/2026 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.47% | — | Codemshop Social TalkAI | 23/11/2024 | 17/6/2026 | The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and including, 1.1.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7) | 0.22% | — | Rockwellautomation Factorytalk View | 12/11/2024 | 17/6/2026 | A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by… | |
| Aplazada | Alta (8.4) | 0.17% | — | TalkatoneAI | 30/10/2024 | 17/6/2026 | The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.talkatone.vedroid.ui.launcher.OutgoingCallInterceptor component. | |
| Analizada | Alta (8.7) | 0.55% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+4 | 14/10/2024 | 17/6/2026 | CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To… |