Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3090▲ 519 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
21.656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.38% | — | AdministratorAI | 26/6/2026 | 26/6/2026 | Administrator SQL Injection in Popup box <= 6.0.1 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Blocksy Companion PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Geminilabs Site ReviewsAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | GetgenieAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. | |
| Aplazada | Alta (8.5) | 0.58% | — | Blocksy Companion PROAI | 26/6/2026 | 26/6/2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Adenion Blog2socialAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Trinity BackupAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Gutenverse CompanionAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | BNE TestimonialsAI | 26/6/2026 | 5/10/2026 | Cross Site Scripting (XSS) de Contribuidor en BNE Testimonials versiones menor o igual a 2.0.8. | |
| Pendiente de análisis | Alta (8) | 1.3% | — | Dell Csi-powerstoreAIDell Csi-unityAIDell Csi-powerflexAIDell Csi-powermaxAI | 26/6/2026 | 26/6/2026 | Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially… | |
| Aplazada | Crítica (9.2) | 0.41% | — | Setracker2 Android Companion APPAI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access. | |
| Analizada | Media (5.3) | 0.31% | — | Apple Swiftnio Http/2 | 25/6/2026 | 30/6/2026 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation… | |
| Aplazada | Alta (8.5) | 0.58% | — | Postsnippets Post SnippetsAI | 25/6/2026 | 25/6/2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | |
| Analizada | Alta (7.2) | 0.68% | — | Aten Unizon | 24/6/2026 | 27/6/2026 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.2) | 2.2% | — | Aten Unizon | 24/6/2026 | 27/6/2026 | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the ImportDeviceList method. The… | |
| Analizada | Alta (7.2) | 2.2% | — | Aten Unizon | 24/6/2026 | 27/6/2026 | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the restoreDB method. The issue results… | |
| Analizada | Alta (7.5) | 1.9% | — | Aten Unizon | 24/6/2026 | 27/6/2026 | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.5) | 1.5% | — | Aten Unizon | 24/6/2026 | 27/6/2026 | ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the uploadSSL method. The issue… | |
| Analizada | Media (6.5) | 1.5% | — | Aten Unizon | 24/6/2026 | 27/6/2026 | ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLicense method. The… | |
| Analizada | Crítica (10) | 0.21% | — | Google Gemini-cliGoogle Run-gemini-cli | 24/6/2026 | 2/7/2026 | Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted… | |
| Aplazada | Alta (7.2) | 0.42% | — | Joomunited WP Meta SEOAI | 24/6/2026 | 29/6/2026 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18. When the plugin's `wpmsTemplateRedirect()` hook detects a 404, it concatenates `$_SERVER['HTTP_HOST']` with the raw… | |
| Aplazada | Media (6.4) | 0.36% | — | Joomunited WP Latest PostsAI | 24/6/2026 | 25/6/2026 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0.11. This is due to insufficient output escaping in the field() and loop() functions, which extract the raw src attribute value from <img> tags… | |
| Aplazada | Alta (7) | 0.18% | — | QOS Logback-coreAIJaninoAI | 24/6/2026 | 1/7/2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by compromising an existing logback configuration file or by injecting an… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Signup SigninAI | 24/6/2026 | 29/6/2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore… | |
| Aplazada | Media (6.4) | 0.33% | — | Joomunited WP Meta SEOAI | 24/6/2026 | 29/6/2026 | The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web… |