Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3090▲ 519 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

21.656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.38%—AdministratorAI26/6/202626/6/2026
Administrator SQL Injection in Popup box <= 6.0.1 versions.
AplazadaMedia (5.3)0.31%—Blocksy Companion PROAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
AplazadaMedia (6.5)0.37%—Geminilabs Site ReviewsAI26/6/202626/6/2026
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
AplazadaMedia (6.5)0.37%—GetgenieAI26/6/202626/6/2026
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
AplazadaAlta (8.5)0.58%—Blocksy Companion PROAI26/6/202626/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
AplazadaAlta (7.1)0.25%—Adenion Blog2socialAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
AplazadaAlta (7.5)0.39%—Trinity BackupAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions.
AplazadaAlta (7.5)0.35%—Gutenverse CompanionAI26/6/202626/6/2026
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
AplazadaMedia (6.5)0.22%—BNE TestimonialsAI26/6/20265/10/2026
Cross Site Scripting (XSS) de Contribuidor en BNE Testimonials versiones menor o igual a 2.0.8.
Pendiente de análisisAlta (8)1.3%—Dell Csi-powerstoreAIDell Csi-unityAIDell Csi-powerflexAIDell Csi-powermaxAI26/6/202626/6/2026
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially…
AplazadaCrítica (9.2)0.41%—Setracker2 Android Companion APPAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
AnalizadaMedia (5.3)0.31%—Apple Swiftnio Http/225/6/202630/6/2026
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation…
AplazadaAlta (8.5)0.58%—Postsnippets Post SnippetsAI25/6/202625/6/2026
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
AnalizadaAlta (7.2)0.68%—Aten Unizon24/6/202627/6/2026
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (7.2)2.2%—Aten Unizon24/6/202627/6/2026
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the ImportDeviceList method. The…
AnalizadaAlta (7.2)2.2%—Aten Unizon24/6/202627/6/2026
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the restoreDB method. The issue results…
AnalizadaAlta (7.5)1.9%—Aten Unizon24/6/202627/6/2026
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaMedia (6.5)1.5%—Aten Unizon24/6/202627/6/2026
ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the uploadSSL method. The issue…
AnalizadaMedia (6.5)1.5%—Aten Unizon24/6/202627/6/2026
ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLicense method. The…
AnalizadaCrítica (10)0.21%—Google Gemini-cliGoogle Run-gemini-cli24/6/20262/7/2026
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted…
AplazadaAlta (7.2)0.42%—Joomunited WP Meta SEOAI24/6/202629/6/2026
The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18. When the plugin's `wpmsTemplateRedirect()` hook detects a 404, it concatenates `$_SERVER['HTTP_HOST']` with the raw…
AplazadaMedia (6.4)0.36%—Joomunited WP Latest PostsAI24/6/202625/6/2026
The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0.11. This is due to insufficient output escaping in the field() and loop() functions, which extract the raw src attribute value from <img> tags…
AplazadaAlta (7)0.18%—QOS Logback-coreAIJaninoAI24/6/20261/7/2026
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by compromising an existing logback configuration file or by injecting an…
AplazadaCrítica (9.8)0.82%—Signup SigninAI24/6/202629/6/2026
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore…
AplazadaMedia (6.4)0.33%—Joomunited WP Meta SEOAI24/6/202629/6/2026
The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web…