Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 2.1% | — | Kirisun Fujian KelixunAI | 23/5/2025 | 17/6/2026 | A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.15% | — | Felixtz Modern-pollsAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in felixtz Modern Polls modern-polls allows Stored XSS.This issue affects Modern Polls: from n/a through <= 1.0.10. | |
| Aplazada | Media (6.3) | 0.46% | — | Perforce Helix ALMAI | 15/4/2025 | 17/6/2026 | Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists. | |
| Analizada | Media (6.3) | 0.16% | — | Felixker Wordpress/plugin Upgrade Time OUT Plugin | 9/4/2025 | 17/6/2026 | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Media (6.9) | 0.46% | — | Mingyuefusu TushuguanlixitongAI | 24/3/2025 | 17/6/2026 | A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access… | |
| Analizada | Media (5.6) | 0.57% | — | Apache Felix Http Webconsole Plugin | 12/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue. | |
| Analizada | Media (6.1) | 0.69% | — | Apache Felix Webconsole | 10/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue. | |
| Aplazada | Media (5.4) | 0.37% | — | Trellix Epolicy OrchestratorAI | 20/12/2024 | 17/6/2026 | Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator. | |
| Aplazada | Media (6.5) | 0.41% | — | Devfelixmoira Poll BuilderAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devfelixmoira Poll Builder poll-builder allows Stored XSS.This issue affects Poll Builder: from n/a through <= 1.3.5. | |
| Aplazada | Alta (8.2) | 0.59% | — | Heolixfy Flexible Woocommerce Checkout Field EditorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: from n/a through 2.0.1. | |
| Aplazada | Media (5.4) | 0.34% | — | Felixwelberg Extended Post StatusAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19. | |
| Aplazada | Media (6.1) | 0.37% | — | FlixitaAI | 6/12/2024 | 17/6/2026 | The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Crítica (9.8) | 2.5% | — | Trellix Enterprise Security Manager | 29/11/2024 | 17/6/2026 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user. | |
| Analizada | Alta (8.2) | 0.44% | — | Trellix Enterprise Security Manager | 29/11/2024 | 17/6/2026 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints. | |
| Aplazada | Alta (8.7) | 0.49% | — | Perforce Helix CoreAI | 11/11/2024 | 17/6/2026 | In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek. | |
| Aplazada | Alta (8.7) | 0.49% | — | Perforce Helix CoreAI | 11/11/2024 | 17/6/2026 | In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek. | |
| Aplazada | Alta (8.7) | 0.49% | — | Perforce Helix CoreAI | 11/11/2024 | 17/6/2026 | In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Fujian Kelixin Communication Command AND Dispatch PlatformAI | 8/10/2024 | 17/6/2026 | Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php. | |
| Analizada | Alta (8.7) | 0.69% | — | Netflix E2nest | 27/9/2024 | 17/6/2026 | A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a | |
| Aplazada | Media (5.8) | 0.20% | — | Perforce Helix CoreAI | 25/9/2024 | 17/6/2026 | In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified. | |
| Analizada | Media (5.3) | 0.22% | — | Devfelixmoira Limit Login Attempts Plus | 19/9/2024 | 17/6/2026 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header… | |
| Analizada | Alta (7.5) | 0.38% | — | Trellix Intrusion Prevention System Manager | 5/9/2024 | 17/6/2026 | This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager. | |
| Analizada | Media (5.3) | 0.39% | — | Trellix Intrusion Prevention System Manager | 5/9/2024 | 17/6/2026 | This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly | |
| Analizada | Alta (7.5) | 0.73% | — | Apache Helix | 20/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not plan to release a version that fixes this… | |
| Aplazada | Crítica (9.8) | 0.77% | — | Kirisun Fujian KelixunAI | 9/7/2024 | 17/6/2026 | Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php. |