Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

21.649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.25%—Dani-garcia VaultwardenAI15/7/202615/7/2026
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left SsoAuth records intact after failed token…
AplazadaMedia (6.5)0.52%—Caxperts Universalplantviewer Webservices ServerAI14/7/202615/7/2026
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
AplazadaBaja (2.1)0.45%—Zhinianboke Xianyu-auto-replyAI14/7/202615/7/2026
A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched…
AplazadaMedia (5.5)0.50%—Zhinianboke Xianyu-auto-replyAI14/7/202615/7/2026
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has…
AnalizadaAlta (8.6)0.33%—Adobe Animate14/7/202628/8/2026
Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended…
AnalizadaAlta (8.1)0.24%—Adobe Animate14/7/202628/8/2026
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
AnalizadaAlta (7.7)0.22%—Adobe Animate14/7/202628/8/2026
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is…
AnalizadaAlta (7.7)0.72%—Adobe Animate14/7/202628/8/2026
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is…
AnalizadaAlta (7.9)0.26%—Adobe Animate14/7/202628/8/2026
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
AnalizadaAlta (8.2)0.89%—Adobe Animate14/7/202628/8/2026
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is…
AnalizadaAlta (7.2)12%⚠ Explotación activa💥 PoCSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
AnalizadaCrítica (10)6.8%⚠ Explotación activa💥 ExploitSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
AplazadaMedia (4.7)0.30%—Netgear Nighthawk RAXAI14/7/202615/7/2026
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
AplazadaMedia (4.9)0.15%—Netgear Xr1000AINetgear NighthawkAI14/7/202615/7/2026
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI14/7/202615/7/2026
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now…
Pendiente de análisisAlta (8.2)0.22%—Allen Bradley Compactlogix 5380AIAllen Bradley Controllogix 5580AIAllen Bradley EN4 Communication ModuleAI14/7/202614/7/2026
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a…
AplazadaBaja (2.1)0.33%—Itsourcecode Electronic Judging SystemAI14/7/202615/7/2026
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /intrams/admin/add_judges.php. This manipulation of the argument fname causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaAlta (8.7)0.78%—Luci-app-banipAI13/7/202615/7/2026
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the…
AplazadaMedia (5.1)0.57%—Phoenixframework Phoenix Live ViewAI13/7/202613/7/2026
Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2 functions in…
AplazadaAlta (7.2)0.54%—Shapedplugin Real TestimonialsAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
AplazadaCrítica (10)0.56%💥 PoCRealtyna Organic IDXAI13/7/202613/7/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.
AplazadaMedia (5.3)0.29%—Presstigers Universal ClocksAI13/7/202613/7/2026
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.
AplazadaMedia (6.5)0.33%—Knitpay Razorpay Payment Links FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.
AplazadaAlta (7.2)0.27%—Denishua Wpjam BasicAI13/7/202613/7/2026
Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.
AplazadaAlta (8.8)0.52%—Denishua Wpjam BasicAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.