Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)1.0%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the…
AplazadaMedia (4.3)0.21%—Wpmapplugins Basic Interactive World MAPAI16/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Basic Interactive World Map basic-interactive-world-map allows Cross Site Request Forgery.This issue affects Basic Interactive World Map: from n/a through <= 2.7.
AplazadaMedia (5.3)0.23%—Xpixelgroup BasicsrAI12/3/202517/6/2026
XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable.
AplazadaAlta (7.1)0.26%—Sysbasics Customize MY Account FOR WoocommerceAI14/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SysBasics Customize My Account for WooCommerce customize-my-account-for-woocommerce allows Reflected XSS.This issue affects Customize My Account for WooCommerce: from n/a through <= 2.8.22.
AnalizadaMedia (4.3)0.24%—Ikjweb Zstore Manager Basic30/1/202517/6/2026
The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's…
AnalizadaAlta (7.3)0.32%—Basic Http Authentication Project Basic Http Authentication9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.
AplazadaAlta (7.8)0.22%—Edgecross Basic Software FOR WindowsAIEdgecross Basic Software FOR DevelopersAI19/12/202417/6/2026
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and…
AplazadaAlta (7.8)0.16%—Edgecross Basic Software FOR WindowsAIEdgecross Basic Software FOR DevelopersAI19/12/202417/6/2026
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or…
AplazadaMedia (5.4)0.41%—Opentools Woocommerce Basic OrdernumbersAI16/12/202417/6/2026
Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers woocommerce-basic-ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through <= 1.4.4.
AplazadaMedia (6.5)0.26%—Bnisia IA MAP Analytics BasicAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bnisia IA Map Analytics Basic ia-map-analytics-basic allows DOM-Based XSS.This issue affects IA Map Analytics Basic: from n/a through <= 20170413.
AnalizadaCrítica (10)1.00%—Siemens Telecontrol Server Basic12/11/202417/6/2026
A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 32 to 64…
AplazadaAlta (7.1)0.29%—Laura20 Wp-basicsAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in laura20 WP-Basics wp-basics allows Reflected XSS.This issue affects WP-Basics: from n/a through <= 2.0.
AplazadaMedia (6.1)0.38%—Sysbasics Customize MY Account FOR WoocommerceAI9/11/202417/6/2026
The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 2.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.5)0.26%—Sysbasics Shortcode FOR Elementor TemplatesAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics Shortcode For Elementor Templates allows Stored XSS.This issue affects Shortcode For Elementor Templates: from n/a through 1.0.0.
AplazadaMedia (6.4)0.32%—WP Cleanup AND Basic FunctionsAI5/10/202417/6/2026
The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to…
AnalizadaAlta (8.7)0.52%—Expressjs Basic-auth-connect30/9/202417/6/2026
basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
ModificadaMedia (4.4)0.19%—Codesys Oscat Basic Library10/9/202417/6/2026
Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.
AplazadaMedia (5.3)0.46%—Siemens Simatic Energy Manager BasicAISiemens Simatic Energy Manager PROAISiemens Simatic IPC DiagbaseAISiemens Simatic IPC DiagmonitorAI+29/7/202417/6/2026
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1). Unified Automation .NET based OPC UA…
AnalizadaAlta (7.8)0.18%—Cisco Crosswork Network Services OrchestratorCisco Confd Basic16/5/202417/6/2026
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI…
AnalizadaAlta (7.8)0.34%—Cisco Confd BasicCisco Confd PremiumCisco Crosswork Network Services Orchestrator16/5/202417/6/2026
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI…
AplazadaMedia (6.5)0.66%—Wpkube Simple Basic Contact FormAI14/5/202417/6/2026
The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed…
AplazadaMedia (6.1)0.51%—Wpkube Simple Basic Contact FormAI14/5/202417/6/2026
The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (4.1)0.36%—Mingsoft MS BasicAI7/5/202417/6/2026
Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.
AplazadaMedia (4.3)0.20%—Alumnionline WEB Services LLC WP ADA Compliance Check BasicAI24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AlumniOnline Web Services LLC WP ADA Compliance Check Basic.This issue affects WP ADA Compliance Check Basic: from n/a through 3.1.3.
AplazadaMedia (4.3)0.23%—Typps Calendarista Basic EditionAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.
Orbitaley — Vulnerabilidades