Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.72%—AdminerAI20/8/20261/9/2026
Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method.…
AplazadaMedia (6.8)0.43%—Wpase Admin AND Site EnhancementsAI20/8/202626/8/2026
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
AnalizadaAlta (7.5)0.13%—Oracle Peoplesoft Lease Administration18/8/202610/9/2026
Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease…
AplazadaMedia (6.5)0.22%—Dynamiapps Frontend AdminAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
Pendiente de análisisAlta (8.9)0.43%—HP WEB JetadminAI17/8/202631/8/2026
HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism.
AplazadaCrítica (9.8)0.84%—Dynamiapps Frontend AdminAI16/8/202620/8/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the…
AplazadaMedia (4.4)0.33%—Weblizar Admin Custom LoginAI16/8/202620/8/2026
The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaCrítica (9.3)0.40%—Church AdminAI13/8/202614/8/2026
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
AplazadaAlta (8.8)0.50%—Pimcore Admin Classic BundleAI12/8/202616/9/2026
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL…
AplazadaMedia (6.5)0.37%—Wpclever WPC Admin ColumnsAI12/8/202626/8/2026
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.
AplazadaAlta (8.8)0.59%—Dynamiapps Frontend AdminAI11/8/202612/8/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above…
AplazadaAlta (8.8)0.43%—Pimcore Admin-ui-classic-bundleAI11/8/20263/9/2026
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can…
AplazadaBaja (2)0.38%—Saithink SaiadminAI10/8/202612/8/2026
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has…
AplazadaAlta (7.5)0.50%—Admin Safety GuardAI8/8/202626/8/2026
The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles,…
AnalizadaMedia (6.5)0.45%—Dell Openmanage Server Administrator7/8/20268/8/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
AnalizadaCrítica (9.8)0.53%—Dell Openmanage Server Administrator7/8/20268/8/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AplazadaMedia (5.4)0.24%—Revenue Administration Turkiye E-signatureAI7/8/202626/8/2026
Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0.
AnalizadaCrítica (9.8)0.61%—Microsoft Windows Admin Center7/8/20267/8/2026
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (9.8)0.77%—FineadminAI6/8/202631/8/2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
AplazadaCrítica (9.8)0.55%—Dynamiapps Frontend AdminAI6/8/202612/8/2026
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
AplazadaBaja (2.1)0.32%—Chetans9 Core-php-admin-panelAI4/8/202612/8/2026
A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack…
AplazadaCrítica (9.8)0.47%—FastadminAI3/8/20269/9/2026
SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component
AplazadaMedia (5.4)0.23%—Admin Columns FOR ACF FieldsAI1/8/202626/8/2026
The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users…
AplazadaAlta (8.8)0.21%—Prestashop TotadministrativemandateAI31/7/202631/8/2026
PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link.
AnalizadaCrítica (9.4)0.67%—Pgadmin 431/7/20265/8/2026
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>,…