Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Wppa WP Photo Album PlusAI | 25/6/2026 | 25/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005. | |
| Aplazada | Media (5.3) | 0.39% | — | SearchplusAI | 24/6/2026 | 25/6/2026 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability check and missing nonce validation on the searchplus_save_token_action_callback() and searchplus_reset_token_action_callback() functions, both… | |
| Aplazada | Alta (8.8) | 0.37% | — | Akin Software Computer Import Export Industry AND Trade LTD CafeplusAI | 23/6/2026 | 23/6/2026 | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CafePlus: from 12.05.03 before 12.05.04. | |
| Pendiente de análisis | Crítica (9) | 2.5% | 💥 PoC | Manageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI | 23/6/2026 | 24/6/2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | |
| Aplazada | Media (4.9) | 0.47% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (6.3) | 0.37% | — | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+3 | 17/6/2026 | 11/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction… | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wppa WP Photo Album PlusAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. | |
| Aplazada | Alta (8.1) | 3.6% | 💥 PoC | UpdraftplusAI | 11/6/2026 | 23/7/2026 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature… | |
| Analizada | Media (6.5) | 0.30% | — | Samsung Plus TV | 5/6/2026 | 30/6/2026 | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information. | |
| Aplazada | Media (6.5) | 0.38% | — | Masterstudy LMS PRO PlusAI | 4/6/2026 | 22/7/2026 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Alta (7.2) | 0.18% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Analizada | Alta (7.2) | 0.18% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Analizada | Alta (7.3) | 0.29% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Analizada | Alta (7.3) | 0.35% | — | ABB T-mac Plus | 3/6/2026 | 22/7/2026 | Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. | |
| Aplazada | Media (4.3) | 0.19% | — | Google Plus ONE BottomAI | 2/6/2026 | 22/7/2026 | The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin's settings,… | |
| Aplazada | Media (6.4) | 0.33% | — | Theplus Plus Addons FOR ElementorAI | 29/5/2026 | 21/7/2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_direction value is… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wordplus BP Better MessagesAI | 27/5/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a through <= 2.14.16. | |
| Aplazada | Media (6.4) | 0.32% | — | Google Plus Link NameAI | 27/5/2026 | 17/6/2026 | The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes ('id' and 'name') in the gplusnamelink_generate() function,… | |
| Aplazada | Media (5.2) | 0.13% | — | CP Plus Wi-fi CameraAI | 25/5/2026 | 23/7/2026 | This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private… | |
| Modificada | Crítica (9.2) | 2.7% | 💥 PoC | F5 Nginx Open SourceF5 Nginx PlusF5 DOSF5 Nginx Gateway Fabric+8 | 22/5/2026 | 25/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple… | |
| Analizada | Alta (7.7) | 0.59% | — | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information. | |
| Analizada | Crítica (10) | 46% | ⚠ Explotación activa💥 Exploit | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | |
| Analizada | Crítica (10) | 1.8% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+28 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. |