Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.7) | 0.40% | — | Linuxfoundation Backstage/integration | 7/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by integration functions that construct API URLs,… | |
| Analizada | Media (5.6) | 0.10% | — | Gallagher Hanwha VMS IntegrationGallagher NX Witness VMS Integration | 3/3/2026 | 17/8/2026 | Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and… | |
| Aplazada | Media (6.4) | 0.28% | — | Printful Integration FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.11 via the advanced size chart REST API endpoint. This is due to insufficient validation of user-supplied URLs before passing them to the download_url() function. This… | |
| Analizada | Media (5.4) | 0.17% | — | IBM Webmethods Integration Server | 17/2/2026 | 17/6/2026 | IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (6.5) | 0.35% | — | Tanium Partner Integration | 5/2/2026 | 17/6/2026 | Tanium addressed an incorrect default permissions vulnerability in Partner Integration. | |
| Aplazada | Media (6.5) | 0.36% | — | IBM Webmethods IntegrationAIIBM Integration ServerAI | 5/2/2026 | 17/6/2026 | IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM webMethods Integration could disclose sensitive user information in server responses. | |
| Analizada | Media (6.5) | 0.25% | — | Dell Openmanage Network Integration | 29/1/2026 | 17/6/2026 | Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Media (5.3) | 0.20% | — | Popcashnet Code Integration ToolAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in PopCash PopCash.Net Code Integration Tool popcashnet-code-integration-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PopCash.Net Code Integration Tool: from n/a through <= 1.8. | |
| Aplazada | Media (6.5) | 0.29% | — | Hyyan Woo-poly-integrationAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0. | |
| Aplazada | Media (5.9) | 0.24% | — | Themeum Tutor LMS Bunnynet IntegrationAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS BunnyNet Integration tutor-lms-bunnynet-integration allows DOM-Based XSS.This issue affects Tutor LMS BunnyNet Integration: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.3) | 0.28% | — | Crmperks Integration FOR Contact Form 7 HubspotAI | 23/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Retrieve Embedded Sensitive Data.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Phrase TMS IntegrationAI | 17/1/2026 | 17/6/2026 | The Phrase TMS Integration for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_delete_log' AJAX endpoint in all versions up to, and including, 4.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.34% | — | Mailerlite Woocommerce IntegrationAI | 16/1/2026 | 17/6/2026 | The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Integration Opvius AI FOR WoocommerceAI | 14/1/2026 | 17/6/2026 | The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it… | |
| Aplazada | Alta (7.5) | 0.34% | — | Cedcommerce Ced-good-market-integrationAIPHPAI | 29/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce CedCommerce Integration for Good Market ced-good-market-integration allows PHP Local File Inclusion.This issue affects CedCommerce Integration for Good Market: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.6) | 0.33% | — | Crmperks Integration FOR Contact Form 7 HubspotAI | 24/12/2025 | 5/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI | 15/12/2025 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. | |
| Aplazada | Alta (8.8) | 0.43% | — | Pentaho Data IntegrationAIPentaho Analytics Community Dashboard EditorAI | 15/12/2025 | 17/6/2026 | Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods. | |
| Aplazada | Media (4.3) | 0.16% | — | Kirim Email Woocommerce IntegrationAI | 12/12/2025 | 17/6/2026 | The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9. This is due to missing nonce validation on the plugin's settings page. This makes it possible for unauthenticated attackers to modify the plugin's API credentials and… | |
| Analizada | Alta (8.8) | 0.47% | — | IBM Webmethods Integration | 20/11/2025 | 17/6/2026 | IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data. | |
| Aplazada | Alta (7.1) | 0.13% | — | Integrationshotelrunner Hotelrunner Booking WidgetAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in integrationshotelrunner HotelRunner Booking Widget hotelrunner allows Stored XSS.This issue affects HotelRunner Booking Widget: from n/a through <= 1.6. | |
| Aplazada | Alta (7.2) | 0.48% | — | Official Integration FOR BillingoAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official Integration for Billingo: from n/a through <= 4.3.0. | |
| Aplazada | Media (6.4) | 0.19% | — | Material Design Iconic Font IntegrationAI | 22/10/2025 | 17/6/2026 | The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdiconic' shortcode in all versions up to, and including, 2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.30% | — | Xx2wp Integration ToolsAI | 18/10/2025 | 17/6/2026 | The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. This is due to the plugin not properly sanitizing user input and output of the 'post_id' parameter. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.22% | — | Modern Minds Magento 2 Wordpress IntegrationAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1. |