Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.41% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | |
| Analizada | Media (6.5) | 0.37% | — | Avaya Media ServerSick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. | |
| Analizada | Media (5.4) | 0.29% | — | Sick Field Analytics | 12/6/2025 | 17/6/2026 | The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source. | |
| Analizada | Alta (7.5) | 0.49% | — | Sick Baggage AnalyticsSick Enterprise AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product. | |
| Modificada | Alta (8.8) | 0.18% | — | Codepeople Calculated Fields Form | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This issue affects Calculated Fields Form: from n/a through <= 5.3.58. | |
| Aplazada | Media (5.9) | 0.25% | — | Unreal Themes ACF Yandex Maps FieldAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unreal Themes ACF: Yandex Maps Field acf-yandex-maps-field allows Stored XSS.This issue affects ACF: Yandex Maps Field: from n/a through <= 1.1. | |
| Analizada | Media (4.8) | 0.31% | — | Codepeople Calculated Fields Form | 15/5/2025 | 17/6/2026 | The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.1) | 0.58% | 💥 Exploit | F1logic Custom Field Manager | 15/5/2025 | 17/6/2026 | The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Custom Checkout Fields FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce custom-checkout-fields-for-woocommerce allows Stored XSS.This issue affects Custom Checkout Fields for WooCommerce: from n/a through <= 1.8.3. | |
| Analizada | Media (4.8) | 0.27% | — | Codepeople Calculated Fields Form | 1/5/2025 | 17/6/2026 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.27% | — | Codepeople Calculated Fields Form | 29/4/2025 | 17/6/2026 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.5) | 0.75% | — | Zamartz Checkout Field Visibility FOR WoocommerceAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zamartz Checkout Field Visibility for WooCommerce checkout-field-visibility-for-woocommerce allows PHP Local File Inclusion.This issue affects Checkout Field Visibility for WooCommerce: from n/a… | |
| Aplazada | Alta (7.1) | 0.29% | — | Danielpataki Acf-google-font-selector-fieldAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in danielpataki ACF: Google Font Selector acf-google-font-selector-field allows Reflected XSS.This issue affects ACF: Google Font Selector: from n/a through <= 3.0.1. | |
| Aplazada | Media (4.3) | 0.27% | — | SAP Field Logistics Manage LogisticsAI | 22/4/2025 | 17/6/2026 | SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability are not impacted. | |
| Aplazada | Alta (7.1) | 0.29% | — | Caalami Acf-link-picker-fieldAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced Custom Fields: Link Picker Field acf-link-picker-field allows Reflected XSS.This issue affects Advanced Custom Fields: Link Picker Field: from n/a through <= 1.2.8. | |
| Aplazada | Alta (7.1) | 0.21% | — | Theode Language-fieldAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field language-field allows Stored XSS.This issue affects Language Field: from n/a through <= 0.9. | |
| Aplazada | Media (4.3) | 0.40% | — | Termel Bulk Fields EditorAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in termel Bulk Fields Editor bulk-user-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Fields Editor: from n/a through <= 1.8.0. | |
| Analizada | Media (6.1) | 0.26% | — | Chapterthree Rapidoc OAS Field Formatter | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1. | |
| Analizada | Media (6.1) | 0.26% | — | Upstreamable Link Field Display Mode Formatter | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0. | |
| Analizada | Alta (7.5) | 0.43% | — | Canonical Linux-bluefield | 31/3/2025 | 17/6/2026 | Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package. | |
| Aplazada | Media (4.3) | 0.19% | — | Silverplugins217 Custom-fields-account-registration-for-woocommerceAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Cross Site Request Forgery.This issue affects Custom Fields Account Registration For Woocommerce: from n/a through <= 1.1. | |
| Aplazada | Media (4.3) | 0.20% | — | Custom Field FOR WP JOB ManagerAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager custom-field-for-wp-job-manager allows Cross Site Request Forgery.This issue affects Custom Field For WP Job Manager: from n/a through <= 1.4. | |
| Aplazada | Alta (8.1) | 1.0% | — | NTM Custom Field List WidgetAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget custom-field-list-widget allows PHP Local File Inclusion.This issue affects custom-field-list-widget: from n/a through <= 1.5.1. | |
| Aplazada | Alta (8.4) | 0.21% | — | Siemens Simatic Field PG M5AISiemens Simatic Field PG M6AISiemens Simatic IPC Bx-21aAISiemens Simatic IPC Bx-32aAI+28 | 11/3/2025 | 8/9/2026 | A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC… | |
| Aplazada | Alta (8.4) | 0.21% | — | Siemens Simatic Field PG M5AISiemens Simatic IPC Bx-21aAISiemens Simatic IPC Bx-32aAISiemens Simatic IPC Bx-39aAI+27 | 11/3/2025 | 8/9/2026 | A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC… |