Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.71% | — | Ivanti Xtraction | 14/7/2026 | 6/8/2026 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Properfraction MailoptinAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3. | |
| Aplazada | Alta (7.5) | 0.51% | — | Qodeinteractive DORAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Pluginus Active Products Tables FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.5) | 0.48% | — | Notifications FOR Forms AND Wordpress ActionsAI | 6/7/2026 | 6/7/2026 | The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server. | |
| Aplazada | Media (4.3) | 0.14% | — | Properfraction Crawlwp SEOAI | 5/7/2026 | 6/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16. | |
| Pendiente de análisis | Baja (3.3) | 0.16% | — | Cubespace Cw0057 Reaction WheelAI | 2/7/2026 | 6/7/2026 | CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. This could allow an attacker with physical access to the product to upload arbitrary malicious firmware to the device without authentication. | |
| Aplazada | Media (4.3) | 0.34% | — | Qodeinteractive QI BlocksAI | 1/7/2026 | 1/7/2026 | The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to modify the stored… | |
| Analizada | Alta (7.5) | 0.56% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Activemq | 30/6/2026 | 2/7/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer them without limit, exhausting the JVM heap. This issue affects… | |
| Analizada | Media (6.1) | 0.68% | — | Apache ActivemqApache Activemq WEB | 30/6/2026 | 2/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that… | |
| Analizada | Alta (7.5) | 0.69% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM.… | |
| Analizada | Alta (7.5) | 0.74% | — | Apache Activemq | 30/6/2026 | 2/7/2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt… | |
| Analizada | Alta (8.1) | 0.51% | — | Apache Activemq | 30/6/2026 | 2/7/2026 | Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.… | |
| Analizada | Alta (7.5) | 0.63% | — | Apache ActivemqApache Activemq Broker | 30/6/2026 | 2/7/2026 | Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker… | |
| Analizada | Alta (7.5) | 0.78% | — | Apache Activemq | 30/6/2026 | 2/7/2026 | Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body… | |
| Analizada | Alta (7.1) | 0.27% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31. | |
| Analizada | Media (6.5) | 0.49% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection), lib/html_reports.php at line 283 stores… | |
| Analizada | Alta (7.2) | 0.50% | 💥 PoC | Cacti | 25/6/2026 | 30/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assigns $selected_items by calling cacti_unserialize(stripslashes(gnrv('selected_graphs_array'))). The… | |
| Analizada | Media (5.4) | 0.32% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[SESS_USER_ID]… | |
| Analizada | Media (6.1) | 0.26% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after login), the function used… | |
| Aplazada | Alta (7.1) | 0.25% | — | WP Activity LOGAI | 25/6/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows Stored XSS.This issue affects WP Activity Log: from n/a through 5.6.3.1. | |
| Analizada | Alta (8.6) | 1.7% | — | Cacti | 25/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by… | |
| Analizada | Alta (8.8) | 0.40% | — | Cacti | 25/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31. |