Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.26%—Thhake Photo Express FOR GoogleAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Express for Google photo-express-for-google allows Reflected XSS.This issue affects Photo Express for Google: from n/a through <= 0.3.2.
AplazadaMedia (4.3)0.16%—Yithemes Yith Paypal Express Checkout FOR WoocommerceAI17/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0.
AnalizadaMedia (4.8)0.26%—Cisco Unified Contact Center Express4/6/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper sanitization of…
AnalizadaMedia (6.7)0.18%—Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+44/6/202517/6/2026
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An…
AnalizadaMedia (6.7)0.17%—Cisco Unified Contact Center Express4/6/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper limitation of a pathname…
AnalizadaAlta (7.2)0.45%—Cisco Unified Contact Center Express4/6/202517/6/2026
This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by sending a crafted Java object to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of an affected…
AnalizadaAlta (7.8)0.19%—Cisco Unified Contact Center Express4/6/202517/6/2026
This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by persuading an authenticated, local user to open a crafted .aef file. A successful exploit could allow the attacker to execute arbitrary code on the host that is running the…
AnalizadaMedia (5.4)0.34%—Cisco SocialminerCisco Unified Contact Center Express4/6/202517/6/2026
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based…
AplazadaAlta (8.7)0.44%—Expressjs MulterAI3/6/202517/6/2026
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an empty string field name. This request causes an unhandled…
AnalizadaMedia (4.3)0.35%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express21/5/202517/6/2026
A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this…
AnalizadaAlta (7.1)0.41%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express21/5/202517/6/2026
A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An…
AplazadaAlta (7.5)0.81%—Expressjs MulterAI19/5/202517/6/2026
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to…
AplazadaAlta (7.5)0.79%—Expressjs MulterAI19/5/202517/6/2026
Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource exhaustion and memory leak issue due to improper stream handling. When the HTTP request stream emits an error, the internal `busboy` stream is not closed, violating Node.js stream safety guidance.…
AnalizadaMedia (4.8)0.31%—Thisfunctional CTT Expresso Para Woocommerce15/5/202517/6/2026
The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaCrítica (9.8)0.56%—Unhandledexpression Trailer9/5/202517/6/2026
lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.
AnalizadaCrítica (9.8)0.48%—Devexpress28/4/202517/6/2026
DevExpress before 23.1.3 allows AsyncDownloader SSRF.
AnalizadaMedia (5.3)0.55%—Devexpress28/4/202517/6/2026
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
AnalizadaCrítica (9.8)0.60%—Devexpress28/4/202517/6/2026
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
AnalizadaCrítica (9.8)0.60%—Devexpress28/4/202517/6/2026
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
AnalizadaMedia (6.1)0.28%—Icegram Express25/4/202517/6/2026
The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaAlta (7.1)0.29%—Hccoder Paypal Express CheckoutAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder PayPal Express Checkout paypal-express-checkout allows Stored XSS.This issue affects PayPal Express Checkout: from n/a through <= 2.1.2.
AplazadaAlta (7.1)0.29%—Expresstechsoftware Memberpress Discord AddonAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon expresstechsoftwares-memberpress-discord-add-on allows Reflected XSS.This issue affects MemberPress Discord Addon: from n/a through <= 1.1.1.
AnalizadaBaja (3.5)0.27%—Icegram Express17/4/202517/6/2026
The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AplazadaMedia (6.5)0.38%—Enituretechnology Small Package Quotes Worldwide Express EditionAI3/4/202517/6/2026
Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.19.
AplazadaMedia (4.7)0.42%—Guru-aliexpress AlinextAI27/3/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in guru-aliexpress AliNext ali2woo-lite allows Phishing.This issue affects AliNext: from n/a through <= 3.5.1.