Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
6578 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.25% | — | Tonec Internet Download Manager | 5/11/2025 | 5/7/2026 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections. | |
| Aplazada | Media (5.3) | 0.35% | — | Melabuwp Download Counter ButtonAI | 5/11/2025 | 17/6/2026 | The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Easy Upload Files During CheckoutAI | 4/11/2025 | 17/6/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files… | |
| Analizada | Media (5.5) | 0.45% | — | Angeljudesuarez Online Loan Management System | 3/11/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 3/11/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 3/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 2/11/2025 | 17/6/2026 | A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Loan Management System | 2/11/2025 | 17/6/2026 | A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Seeyon Zhiyuan OAAI | 30/10/2025 | 17/6/2026 | Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` parameter in thirdpartyController.do. The decoded map values can influence session attributes without sufficient authentication/authorization checks, enabling attackers to assign a session to arbitrary… | |
| Analizada | Alta (7.5) | 0.36% | — | Simple Oauth Project Simple Oauth | 29/10/2025 | 8/10/2026 | La vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en Drupal Simple OAuth (OAuth2) y OpenID Connect permite la omisión de autenticación. Este problema afecta a Simple OAuth (OAuth2) y OpenID Connect: desde 6.0.0 antes de 6.0.7. | |
| Aplazada | Media (6) | 0.14% | — | KeycloakAI | 28/10/2025 | 17/6/2026 | A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user… | |
| Aplazada | Media (5.4) | 0.12% | — | JdownloadsAIJoomlaAI | 28/10/2025 | 8/10/2026 | Múltiples vectores de ataque CSRF en el componente JDownloads 1.0.0-4.0.47 para Joomla fueron descubiertos. | |
| Aplazada | Baja (3.7) | 0.41% | — | KeycloakAI | 28/10/2025 | 31/8/2026 | A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected… | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1 y 5.1 podría permitir a un usuario autenticado provocar el bloqueo del programa debido a una escritura fuera de límites. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1 y 5.1 podría permitir a un usuario autenticado provocar que el programa falle debido al cálculo incorrecto del tamaño de los datos a los que se está apuntando. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1 y 5.1 podría permitir a un usuario autenticado provocar que el programa falle debido a la sobrescritura de un búfer cuando se asigna en la pila. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, y 5.1 podrían permitir a un usuario… | |
| Aplazada | Alta (7.1) | 0.14% | — | Iseremet Reloadly Reloadly-topup-widgetAI | 27/10/2025 | 8/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en iseremet Reloadly reloadly-topup-widget permite XSS almacenado. Este problema afecta a Reloadly: desde n/a hasta menor o igual que 2.0.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Buddydev Activity Plus ReloadedAIBuddypressAI | 27/10/2025 | 8/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en BuddyDev Activity Plus Reloaded para BuddyPress bp-activity-plus-reloaded permite XSS Almacenado. Este problema afecta a Activity Plus Reloaded para BuddyPress: desde n/a hasta menor o igual que… | |
| Aplazada | Media (6.3) | 0.26% | — | Discussion BoardAI | 25/10/2025 | 8/10/2026 | El plugin The Discussion Board - WordPress Forum Plugin para WordPress es vulnerable a la ejecución arbitraria de shortcodes en todas las versiones hasta la 2.5.5, inclusive. Esto se debe a que el software permite a los usuarios ejecutar una acción que no valida correctamente un valor antes de ejecutar do_shortcode.… | |
| Aplazada | Alta (8.7) | 0.49% | — | Karmada DashboardAI | 24/10/2025 | 8/10/2026 | Karmada Dashboard es un panel de control de propósito general, basado en web, para Karmada, que es un proyecto de gestión multi-clúster. Antes de la versión 0.2.0, existe una vulnerabilidad de omisión de autenticación en la API de Karmada Dashboard. Los endpoints de la API de backend (por ejemplo, /api/v1/secret,… | |
| Analizada | Media (6.1) | 0.28% | — | SIR Gnuboard | 23/10/2025 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php. | |
| Analizada | Media (6.5) | 0.23% | — | SIR Gnuboard | 23/10/2025 | 17/6/2026 | gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. | |
| Aplazada | Media (5.4) | 0.30% | — | KeycloakAI | 23/10/2025 | 17/6/2026 | A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a situation where an administrator removes the scope, and assumes that offline… | |
| Aplazada | Media (5.4) | 0.24% | — | KeycloakAI | 23/10/2025 | 17/6/2026 | A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until they expire, overriding the administrator's recent security configuration change.… |