Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.37% | — | Rockwellautomation Factorytalk Activation Manager | 9/9/2025 | 17/6/2026 | A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise. | |
| Analizada | Alta (8.7) | 0.29% | — | Rockwellautomation Factorytalk Analytics Logixai | 9/9/2025 | 1/10/2026 | An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Icons FactoryAI | 15/8/2025 | 17/6/2026 | The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unauthenticated attackers to to delete arbitrary files on the… | |
| Analizada | Alta (8.4) | 0.50% | — | Rockwellautomation Factorytalk Linx | 14/8/2025 | 17/6/2026 | A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers. | |
| Aplazada | Alta (8.5) | 0.14% | — | Rockwellautomation Factorytalk ViewpointAI | 14/8/2025 | 17/6/2026 | A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command prompt, enabling full privilege… | |
| Aplazada | Crítica (9.9) | 0.36% | — | Wpfactory Product XML Feed Manager FOR WoocommerceAI | 14/8/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Remote Code Inclusion.This issue affects Product XML Feed Manager for WooCommerce: from n/a through <= 2.9.3. | |
| Aplazada | Crítica (9.1) | 0.66% | 💥 PoC | Apache AirflowAIAstronomer Dag-factoryAI | 26/7/2025 | 17/6/2026 | dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity vulnerability has been identified in the cicd.yml workflow within the astronomer/dag-factory GitHub repository. The workflow, specifically when triggered by… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpfactory Wishlist FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wishlist for WooCommerce: from n/a through <= 3.2.3. | |
| Aplazada | Media (6.5) | 0.34% | — | Wpfactory Product XML Feed Manager FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product XML Feed Manager for WooCommerce: from n/a through <= 2.9.2. | |
| Analizada | Media (6.5) | 0.40% | — | Two-factor Authentication Project Two-factor Authentication | 8/7/2025 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0. | |
| Aplazada | Crítica (9.1) | 0.50% | 💥 PoC | Webfactory Aibuddy Openai ChatgptAI | 3/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9. | |
| Analizada | Media (5.4) | 0.23% | — | Dfactory Responsive Lightbox | 27/6/2025 | 17/6/2026 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hiyouga Llama-factory | 26/6/2025 | 17/6/2026 | LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, allowing malicious… | |
| Aplazada | Media (5.3) | 0.35% | — | Dfactory Download AttachmentsAI | 20/6/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpfactory CRM ERP Business SolutionAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory CRM ERP Business Solution crm-erp-business-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CRM ERP Business Solution: from n/a through <= 1.13. | |
| Aplazada | Media (4.3) | 0.17% | — | Wpfactory MIN MAX Step Quantity Limits Manager FOR WoocommerceAI | 10/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce product-quantity-for-woocommerce allows Cross Site Request Forgery.This issue affects Min Max Step Quantity Limits Manager for WooCommerce: from n/a through <= 5.1.0. | |
| Modificada | Media (5.4) | 0.26% | — | Wpfactory Change ADD TO Cart Button Text FOR Woocommerce | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce add-to-cart-button-labels-for-woocommerce allows Stored XSS.This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through <= 2.2.2. | |
| Modificada | Media (5.4) | 0.26% | — | Wpfactory Free Shipping BAR | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce allows Stored XSS.This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce:… | |
| Modificada | Media (5.4) | 0.26% | — | Wpfactory Back Button Widget | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget back-button-widget allows Stored XSS.This issue affects Back Button Widget: from n/a through <= 1.6.8. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Custom-emails-for-woocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Emails & Recipients for WooCommerce custom-emails-for-woocommerce allows Stored XSS.This issue affects Additional Custom Emails & Recipients for WooCommerce: from n/a through <= 3.5.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Coupons AND ADD TO Cart BY URL Links FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Coupons & Add to Cart by URL Links for WooCommerce url-coupons-for-woocommerce-by-algoritmika allows Stored XSS.This issue affects Coupons & Add to Cart by URL Links for WooCommerce: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory EAN FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Stored XSS.This issue affects EAN for WooCommerce: from n/a through <= 5.4.6. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Sitewide Discount FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide Discount for WooCommerce: Apply Discount to All Products global-shop-discount-for-woocommerce allows Stored XSS.This issue affects Sitewide Discount for WooCommerce: Apply Discount to All Products:… | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of Goods for WooCommerce cost-of-goods-for-woocommerce allows Stored XSS.This issue affects Cost of Goods for WooCommerce: from n/a through <= 3.7.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Product-notes-for-woocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Notes Tab & Private Admin Notes for WooCommerce product-notes-for-woocommerce allows Stored XSS.This issue affects Product Notes Tab & Private Admin Notes for WooCommerce: from n/a through <= 3.1.0. |