Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.30% | — | Buddyboss Platform | 2/5/2025 | 17/6/2026 | The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.44% | — | Boschrexroth Ctrlx OSAI | 30/4/2025 | 17/6/2026 | A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests. | |
| Analizada | Media (5.1) | 15% | — | Amttgroup Hibos | 27/4/2025 | 17/6/2026 | A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely.… | |
| Aplazada | Media (6.2) | 1.0% | — | WildflyAIRedhat Jboss Enterprise Application PlatformAIJboss MarshallingAI | 7/4/2025 | 19/8/2026 | A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object,… | |
| Analizada | Media (5.9) | 0.27% | — | Robosoft Maps | 4/4/2025 | 17/6/2026 | The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (4.3) | 0.30% | — | CartbossAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in CartBoss CartBoss cartboss allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartBoss: from n/a through <= 4.1.2. | |
| Analizada | Media (5.3) | 7.3% | — | Amttgroup Hibos | 24/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup.php. The manipulation of the argument SwitchVersion/SwitchWrite/SwitchIP/SwitchIndex/SwitchState leads to os command injection. The attack… | |
| Modificada | Alta (8.1) | 0.89% | — | Redhat Wildfly CoreRedhat Data GridRedhat Jboss Enterprise Application Platform | 4/3/2025 | 14/9/2026 | A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI. | |
| Aplazada | Alta (7.1) | 0.39% | — | Josh Harrison Yahoo BossAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Harrison Yahoo BOSS yahoo-boss allows Reflected XSS.This issue affects Yahoo BOSS: from n/a through <= 0.7. | |
| Aplazada | Alta (7.5) | 0.38% | — | Bosscomm If740AI | 28/2/2025 | 17/6/2026 | An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via the update or boot process. | |
| Aplazada | Media (6.5) | 0.21% | — | Bosscomm If740AI | 28/2/2025 | 17/6/2026 | Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack. | |
| Aplazada | Media (6.2) | 0.16% | — | Bosscomm If740AI | 28/2/2025 | 17/6/2026 | Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext. | |
| Analizada | Media (5.4) | 0.24% | — | Buddyboss Platform | 27/2/2025 | 17/6/2026 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Alta (7.5) | 0.46% | — | Qibosoft Qibocms X1 | 20/2/2025 | 17/6/2026 | An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content. | |
| Modificada | Media (6.5) | 0.77% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly | 30/1/2025 | 18/9/2026 | A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to… | |
| Aplazada | Alta (7.1) | 0.17% | — | Shabboscommerce Shabbos AND YOM TOVAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in shabboscommerce Shabbos and Yom Tov shabbos-and-yom-tov allows Stored XSS.This issue affects Shabbos and Yom Tov: from n/a through <= 1.9. | |
| Aplazada | Alta (7.1) | 0.33% | — | TurbosmtpAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in turboSMTP turboSMTP turbosmtp allows Reflected XSS.This issue affects turboSMTP: from n/a through <= 4.6. | |
| Analizada | Baja (2.7) | 0.53% | — | Robosoft Robo Gallery | 7/1/2025 | 17/6/2026 | The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (5.4) | 0.17% | — | Buddyboss LLC Buddyboss ThemeAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61. | |
| Aplazada | Media (5.3) | 0.53% | — | THE African Boss Checkout With Zelle ON WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in The African Boss Checkout with Zelle on Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout with Zelle on Woocommerce: from n/a through 3.1. | |
| Aplazada | Media (5.4) | 0.38% | — | Robosoft Robo GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robo Gallery: from n/a through 3.2.9. | |
| Aplazada | Media (6.1) | 0.36% | — | TurbosmtpAI | 10/12/2024 | 17/6/2026 | The turboSMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Aplazada | Media (4.2) | 0.24% | — | Redhat Single Sign ONAIRedhat Jboss Enterprise Application PlatformAIRedhat Oidc ClientAI | 9/12/2024 | 4/8/2026 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a… | |
| Aplazada | Alta (7.5) | 0.49% | — | Boschrexroth IndradriveAI | 13/11/2024 | 17/6/2026 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages. | |
| Aplazada | Media (6.5) | 0.35% | — | LibosdpAI | 12/11/2024 | 17/6/2026 | libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. At ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid, but names array do not declare all of the range. On a case of… |