Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.23% | — | Joshfabean Bookable Calendar | 13/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13. | |
| Analizada | Alta (7.8) | 0.28% | — | Adobe Photoshop | 13/5/2025 | 17/6/2026 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.28% | — | Adobe Photoshop | 13/5/2025 | 17/6/2026 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.28% | — | Adobe Photoshop | 13/5/2025 | 17/6/2026 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Crítica (9.4) | 0.74% | 💥 PoC | GoshsAI | 6/5/2025 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The function `dispatchReadPump` does not checks the option cli `-c`, thus allowing anyone to execute arbitrary command through… | |
| Aplazada | Media (4.9) | 0.23% | — | Josheli Simple Google Photos GridAI | 24/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in josheli Simple Google Photos Grid simple-google-photos-grid allows Server Side Request Forgery.This issue affects Simple Google Photos Grid: from n/a through <= 1.5. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Saoshyant1994 Saoshyant SliderAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider saoshyant-slider allows Object Injection.This issue affects Saoshyant Slider: from n/a through <= 3.0. | |
| Aplazada | Media (6.5) | 0.38% | — | Lrqa Poshc2AI | 16/4/2025 | 17/6/2026 | An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as an infected machine. | |
| Aplazada | Alta (8.8) | 0.92% | — | Lrqa Nettitude Poshc2AI | 16/4/2025 | 17/6/2026 | A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers to execute arbitrary code via a crafted POST request. | |
| Aplazada | Media (4.3) | 0.19% | — | Yuya Hoshino Bulk Term EditorAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yuya Hoshino Bulk Term Editor bulk-term-editor allows Cross Site Request Forgery.This issue affects Bulk Term Editor: from n/a through <= 1.1.4. | |
| Aplazada | Alta (7.1) | 0.42% | — | Josh Kohlbach Woocommerce-exporterAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Store Exporter woocommerce-exporter allows Reflected XSS.This issue affects Store Exporter: from n/a through <= 2.7.4. | |
| Analizada | Alta (7.8) | 0.41% | — | Adobe Photoshop | 8/4/2025 | 17/6/2026 | Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.5) | 0.24% | — | Joshix SimplishAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joshix Simplish simplish allows Stored XSS.This issue affects Simplish: from n/a through <= 2.6.4. | |
| Aplazada | Alta (7.1) | 0.29% | — | Moshensky CF7 SpreadsheetsAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Reflected XSS.This issue affects CF7 Spreadsheets: from n/a through <= 2.3.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Photoshelter FOR Photographers Blog Feed PluginAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PhotoShelter PhotoShelter for Photographers Blog Feed Plugin photoshelter-official-plugin allows Stored XSS.This issue affects PhotoShelter for Photographers Blog Feed Plugin: from n/a through <= 1.5.7. | |
| Aplazada | Media (5.4) | 0.26% | — | Moshensky CF7 SpreadsheetsAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Spreadsheets: from n/a through <= 2.3.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Josh Harrison Yahoo BossAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Harrison Yahoo BOSS yahoo-boss allows Reflected XSS.This issue affects Yahoo BOSS: from n/a through <= 0.7. | |
| Aplazada | Alta (7.1) | 0.28% | — | Pantho Bihosh PIT Login WelcomeAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pantho Bihosh Pit Login Welcome pit-login-welcome allows Reflected XSS.This issue affects Pit Login Welcome: from n/a through <= 1.1.5. | |
| Aplazada | Crítica (9.8) | 40% | — | Tuoshi Dionlink Lt15dAITuoshi Dionlink Lt21bAI | 27/2/2025 | 17/6/2026 | An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to… | |
| Analizada | Alta (7.8) | 0.16% | — | Mongodb MongoshRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+9 | 27/2/2025 | 17/6/2026 | mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0 | |
| Analizada | Media (6.8) | 0.22% | — | Mongodb Mongosh | 27/2/2025 | 17/6/2026 | The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell output. This may result in the display of falsified messages that appear to originate from mongosh or the underlying operating system,… | |
| Analizada | Alta (8.8) | 0.28% | — | Mongodb Mongosh | 27/2/2025 | 17/6/2026 | The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted text can be used to obfuscate malicious code. This issue affects mongosh versions… | |
| Analizada | Media (6.5) | 0.36% | — | Mongodb Mongosh | 27/2/2025 | 17/6/2026 | The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input and run obfuscated malicious text. This requires user interaction in the form of the user using ‘tab’ to autocomplete text that is a prefix… | |
| Aplazada | Media (6.5) | 0.28% | — | Patternsinthecloud Autoship Cloud FOR Woocommerce Subscription ProductsAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in patternsinthecloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows DOM-Based XSS.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through <= 2.8.0.1. | |
| Analizada | Media (5.4) | 0.25% | — | Patternsinthecloud Autoship Cloud FOR Woocommerce | 21/2/2025 | 5/8/2026 | The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied… |