Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
6578 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Shahjada Download ManagerAI | 26/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.25. | |
| Aplazada | Media (6.5) | 0.22% | — | Pickplugins JOB Board ManagerAI | 26/9/2025 | 9/10/2026 | Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('cross-site scripting') en PickPlugins Job Board Manager permite XSS basado en DOM. Este problema afecta a Job Board Manager: desde n/a hasta 2.1.61. | |
| Aplazada | Alta (7.2) | 0.66% | — | Wpdownloadmanager Wp-downloadmanagerAI | 26/9/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (4.3) | 0.20% | 💥 PoC | Bowo System DashboardAI | 26/9/2025 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing nonce validation on the sd_toggle_logs() function. This makes it possible for unauthenticated attackers to toggle critical logging settings including Page Access… | |
| Aplazada | Media (4.3) | 0.17% | — | Miniorange Oauth Single Sign ONAI | 26/9/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.39% | — | Broadcom Tcpreplay | 23/9/2025 | 17/6/2026 | A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file is processed, the program incorrectly handles memory in the checksum calculation logic at do_checksum_math_liveplay in tcpliveplay.c, leading to a possible denial of service. | |
| Analizada | Media (5.5) | 0.55% | — | Jinher OA | 22/9/2025 | 17/6/2026 | A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Media (5.3) | 0.71% | 💥 Exploit | Connekthq Ajax Load MoreAI | 22/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More ajax-load-more allows Retrieve Embedded Sensitive Data.This issue affects Ajax Load More: from n/a through <= 7.6.0.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Codefish Pinterest Pinboard WidgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7. | |
| Aplazada | Media (6.5) | 0.16% | — | Damian BP BP Disable Activation ReloadedAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Damian BP Disable Activation Reloaded bp-disable-activation-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Disable Activation Reloaded: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Stephanieleary Dashboard NotepadAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Dashboard Notepad dashboard-notepad allows Cross Site Request Forgery.This issue affects Dashboard Notepad: from n/a through <= 1.42. | |
| Aplazada | Media (5.9) | 0.22% | — | Jonathan Brinley Doaj ExportAI | 22/9/2025 | 30/9/2026 | Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Jonathan Brinley DOAJ Export permite XSS Almacenado. Este problema afecta a DOAJ Export: desde n/a hasta 1.0.4. | |
| Analizada | Alta (7.8) | 0.18% | — | Broadcom Tcpreplay | 22/9/2025 | 17/6/2026 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a… | |
| Analizada | Media (5.5) | 0.35% | — | Webkul Qloapps | 21/9/2025 | 17/6/2026 | A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We… | |
| Aplazada | Media (6.1) | 0.22% | — | Download ManagerAI | 19/9/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Fortra Goanywhere Managed File Transfer | 18/9/2025 | 4/8/2026 | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. | |
| Analizada | Alta (8) | 0.51% | — | Aaluoxiang OA System | 16/9/2025 | 17/6/2026 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController | |
| Aplazada | Alta (7.2) | 0.18% | — | Paloaltonetworks User-id Credential AgentAI | 12/9/2025 | 17/6/2026 | — | |
| Aplazada | Baja (2.4) | 0.14% | — | Microsoft 365 DefenderAIPaloaltonetworks Cortex XDRAI | 12/9/2025 | 17/6/2026 | A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are… | |
| Analizada | Baja (2.1) | 0.36% | — | 10oa | 12/9/2025 | 17/6/2026 | A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the file /trial/mvc/item. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be… | |
| Analizada | Baja (2) | 0.73% | — | 10oa | 12/9/2025 | 17/6/2026 | A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such manipulation of the argument File leads to path traversal. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did… | |
| Analizada | Baja (2.1) | 0.36% | — | 10oa | 11/9/2025 | 17/6/2026 | A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early… | |
| Analizada | Baja (2.1) | 0.36% | — | 10oa | 11/9/2025 | 17/6/2026 | A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The manipulation of the argument Name results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about… | |
| Aplazada | Alta (8.7) | 0.63% | — | Google Secops Soar ServerAI | 11/9/2025 | 17/6/2026 | A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions) allows an authenticated attacker with permissions to import Use Cases to achieve Remote Code Execution (RCE) via uploading a malicious ZIP archive containing path… | |
| Aplazada | Baja (2) | 0.25% | — | Lokibhardwaj Php-code-for-unlimited-file-uploadAI | 11/9/2025 | 17/6/2026 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made… |