Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.72% | — | AdminerAI | 20/8/2026 | 1/9/2026 | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method.… | |
| Aplazada | Media (6.8) | 0.43% | — | Wpase Admin AND Site EnhancementsAI | 20/8/2026 | 26/8/2026 | The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it. | |
| Analizada | Alta (7.5) | 0.13% | — | Oracle Peoplesoft Lease Administration | 18/8/2026 | 10/9/2026 | Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Lease… | |
| Aplazada | Media (6.5) | 0.22% | — | Dynamiapps Frontend AdminAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Pendiente de análisis | Alta (8.9) | 0.43% | — | HP WEB JetadminAI | 17/8/2026 | 31/8/2026 | HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism. | |
| Aplazada | Crítica (9.8) | 0.84% | — | Dynamiapps Frontend AdminAI | 16/8/2026 | 20/8/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the… | |
| Aplazada | Media (4.4) | 0.33% | — | Weblizar Admin Custom LoginAI | 16/8/2026 | 20/8/2026 | The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Church AdminAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | |
| Aplazada | Alta (8.8) | 0.50% | — | Pimcore Admin Classic BundleAI | 12/8/2026 | 16/9/2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL… | |
| Aplazada | Media (6.5) | 0.37% | — | Wpclever WPC Admin ColumnsAI | 12/8/2026 | 26/8/2026 | The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators. | |
| Aplazada | Alta (8.8) | 0.59% | — | Dynamiapps Frontend AdminAI | 11/8/2026 | 12/8/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level and above… | |
| Aplazada | Alta (8.8) | 0.43% | — | Pimcore Admin-ui-classic-bundleAI | 11/8/2026 | 3/9/2026 | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can… | |
| Aplazada | Baja (2) | 0.38% | — | Saithink SaiadminAI | 10/8/2026 | 12/8/2026 | A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Alta (7.5) | 0.50% | — | Admin Safety GuardAI | 8/8/2026 | 26/8/2026 | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles,… | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Server Administrator | 7/8/2026 | 8/8/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dell Openmanage Server Administrator | 7/8/2026 | 8/8/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Aplazada | Media (5.4) | 0.24% | — | Revenue Administration Turkiye E-signatureAI | 7/8/2026 | 26/8/2026 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Request Forgery. This issue affects Türkiye's E-Signature: from 2.4.4.0 before 2.5.1.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Microsoft Windows Admin Center | 7/8/2026 | 7/8/2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.8) | 0.77% | — | FineadminAI | 6/8/2026 | 31/8/2026 | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints | |
| Aplazada | Crítica (9.8) | 0.55% | — | Dynamiapps Frontend AdminAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | |
| Aplazada | Baja (2.1) | 0.32% | — | Chetans9 Core-php-admin-panelAI | 4/8/2026 | 12/8/2026 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack… | |
| Aplazada | Crítica (9.8) | 0.47% | — | FastadminAI | 3/8/2026 | 9/9/2026 | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component | |
| Aplazada | Media (5.4) | 0.23% | — | Admin Columns FOR ACF FieldsAI | 1/8/2026 | 26/8/2026 | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users… | |
| Aplazada | Alta (8.8) | 0.21% | — | Prestashop TotadministrativemandateAI | 31/7/2026 | 31/8/2026 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | |
| Analizada | Crítica (9.4) | 0.67% | — | Pgadmin 4 | 31/7/2026 | 5/8/2026 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>,… |