Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.33% | — | Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI | 18/9/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600… | |
| Aplazada | Crítica (10) | 0.64% | — | Saurus CMS Community EditionAI | 19/8/2025 | 5/7/2026 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP code execution. | |
| Aplazada | Alta (8.1) | 0.36% | — | Opennebula Community EditionAIOpennebula Enterprise EditionAI | 3/8/2025 | 17/6/2026 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their… | |
| Aplazada | Crítica (9.1) | 0.57% | — | Saurus CMS Community EditionAI | 1/8/2025 | 17/6/2026 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to… | |
| Aplazada | Crítica (9.8) | 7.9% | 💥 Exploit | Alfresco Community EditionAI | 17/6/2025 | 17/6/2026 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch. | |
| Aplazada | Media (6.8) | 0.40% | — | Portainer Community EditionAI | 17/6/2025 | 17/6/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,… | |
| Analizada | Crítica (9.8) | 84% | 💥 Exploit | Invisioncommunity | 16/5/2025 | 17/6/2026 | Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Shahjahan Jewel Fluent-communityAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Injection.This issue affects FluentCommunity: from n/a through <= 1.2.15. | |
| Analizada | Media (5.9) | 0.44% | — | Steve-community Steve | 15/4/2025 | 17/6/2026 | An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests. | |
| Aplazada | Media (6.3) | 0.14% | — | OtrsAIOtrs Community EditionAI | 27/1/2025 | 17/6/2026 | Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Aplazada | Baja (3.5) | 0.22% | — | OtrsAIOtrs Community EditionAI | 27/1/2025 | 17/6/2026 | An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Aplazada | Media (6.9) | 0.58% | — | Hyland Alfresco Community EditionAIHyland Alfresco Enterprise EditionAI | 18/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.1) | 0.41% | — | Website Toolbox CommunityAI | 12/12/2024 | 17/6/2026 | The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolbox_username’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.1) | 0.56% | — | Community BY PeepsoAI | 21/11/2024 | 17/6/2026 | The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 7.0.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.38% | — | Michael Simpson Community Yard SaleAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale community-yard-sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through <= 1.1.11. | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Simple Music Cloud Community System | 10/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.4) | 0.28% | — | Community BY PeepsoAI | 16/10/2024 | 17/6/2026 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, and profiles when Markdown support is enabled in all versions up to, and including, 6.4.6.1 due to insufficient input… | |
| Modificada | Baja (2) | 0.52% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.3) | 0.69% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of the argument sitio leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.65% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation of the argument image leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (8.2) | 0.38% | — | OtrsAIOtrs Community EditionAI | 26/8/2024 | 17/6/2026 | Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be… | |
| Aplazada | Media (4.9) | 0.36% | — | OtrsAIOtrs Community EditionAI | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: Products based on the ((OTRS)) Community… | |
| Analizada | Media (6.1) | 0.40% | — | Steve-community Steve | 12/8/2024 | 17/6/2026 | SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe… | |
| Analizada | Media (4.8) | 0.35% | — | Community Events Project Community Events | 5/8/2024 | 17/6/2026 | The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.26% | — | Community Events Project Community Events | 22/7/2024 | 17/6/2026 | The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack |