Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.78% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 15/9/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Modificada | Crítica (9.8) | 0.75% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 15/9/2025 | 17/6/2026 | A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. | |
| Analizada | Baja (2.5) | 0.63% | — | Webkul Unopim | 22/8/2025 | 17/6/2026 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious content into exported CSV files. When the… | |
| Analizada | Alta (8.1) | 0.43% | — | Webkul Unopim | 22/8/2025 | 17/6/2026 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these users can bypass intended access controls… | |
| Analizada | Media (6.9) | 0.15% | — | Webkul Unopim | 21/8/2025 | 17/6/2026 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1. | |
| Analizada | Alta (7.3) | 0.48% | — | Webkul Unopim | 21/8/2025 | 17/6/2026 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite.… | |
| Analizada | Media (4.8) | 0.37% | — | Webkul Unopim | 21/8/2025 | 17/6/2026 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Aplazada | Crítica (10) | 0.58% | 💥 PoC | Webkul Medical Prescription Attachment Plugin FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through <=… | |
| Analizada | Alta (8.8) | 9.5% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxApple SafariApple Ipados+6 | 15/7/2025 | 1/10/2026 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Baja (2) | 0.57% | — | Webkul Qloapps | 17/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.1) | 0.23% | — | Webkul Bagisto | 9/6/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can be exploited to steal sensitive user… | |
| Analizada | Media (5.1) | 0.42% | 💥 PoC | Webkul Krayin CRM | 14/4/2025 | 17/6/2026 | A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.29% | — | Inet WebkitAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through <= 1.2.2. | |
| Analizada | Media (4.2) | 0.22% | — | Webkul Qloapps | 18/2/2025 | 17/6/2026 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. | |
| Analizada | Media (5.3) | 0.54% | — | Webkul Qloapps | 10/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long… | |
| Analizada | Media (5.3) | 0.33% | — | Webkul Qloapps | 6/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (4.8) | 0.18% | — | Webkul Unopim | 13/11/2024 | 17/6/2026 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When… | |
| Analizada | Media (5.4) | 0.38% | — | Webkul Unopim | 6/11/2024 | 17/6/2026 | UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies. | |
| Modificada | Media (4.8) | 0.42% | — | Webkul Krayin CRM | 7/10/2024 | 5/7/2026 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. | |
| Analizada | Crítica (9.6) | 0.53% | — | Webkul Krayin CRM | 27/9/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the… | |
| Analizada | Alta (8.8) | 0.53% | — | Webkul Krayin CRM | 27/9/2024 | 17/6/2026 | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated… | |
| Modificada | Alta (7.2) | 1.2% | 💥 PoC | Webkul Qloapps | 25/7/2024 | 17/6/2026 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Media (5.5) | 0.60% | — | Apple SafariApple IpadosApple Iphone OSApple Macos+5 | 14/5/2024 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. | |
| Aplazada | Media (4.6) | 0.93% | — | Telegram WebkAI | 29/4/2024 | 17/6/2026 | In Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type. |