Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
814 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/3/2026 | 17/6/2026 | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the… | |
| Aplazada | Alta (7.1) | 0.62% | — | Netnumber Titan MasterAI | 22/3/2026 | 17/6/2026 | NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files by injecting directory traversal sequences. Attackers can manipulate the path parameter with base64-encoded payloads containing ../ sequences to bypass authorization and… | |
| Aplazada | Media (5.9) | 0.24% | — | Jeweltheme Master Addons FOR ElementorAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows DOM-Based XSS.This issue affects Master Addons for Elementor: from n/a through <= 2.1.3. | |
| Aplazada | Alta (8.8) | 1.1% | — | Master-addons Master Addons FOR ElementorAI | 2/3/2026 | 17/6/2026 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is due to missing capability check. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Crítica (9.2) | 0.77% | — | Asustor Data Master | 25/2/2026 | 17/6/2026 | The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path traversal… | |
| Analizada | Alta (8.3) | 0.27% | — | Asustor Data Master | 25/2/2026 | 17/6/2026 | The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An improper validated TLS/SSL certificates allows a remote attacker can intercept network traffic to perform a Man-in-the-Middle (MitM) attack, which may intercept, modify, or… | |
| Analizada | Crítica (9.3) | 1.5% | 💥 PoC | Insat Masterscada | 24/2/2026 | 17/6/2026 | All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution. | |
| Analizada | Crítica (9.3) | 0.55% | — | Insat Masterscada | 24/2/2026 | 17/6/2026 | InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution. | |
| Aplazada | Alta (7.5) | 0.27% | — | Saiful Islam Sync Master Sheet Product Sync With Google Sheet FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Saiful Islam Sync Master Sheet – Product Sync with Google Sheet for WooCommerce product-sync-master-sheet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sync Master Sheet – Product Sync with Google Sheet for WooCommerce: from n/a… | |
| Aplazada | Alta (8.5) | 0.27% | — | Expresstechsystems Quiz AND Survey MasterAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1. | |
| Aplazada | Media (5.9) | 0.22% | — | Jeweltheme Master Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4. | |
| Aplazada | Media (6.4) | 0.16% | — | Master-addons Master Addons FOR ElementorAI | 20/2/2026 | 17/6/2026 | The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_table_btn_text' parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (4.3) | 0.11% | — | Themastercut Revision-manager-tmcAI | 19/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross Site Request Forgery.This issue affects Revision Manager TMC: from n/a through <= 2.8.22. | |
| Aplazada | Media (4.3) | 0.19% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Alta (7.5) | 0.39% | — | Cmsmasters Content ComposerAI | 19/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5. | |
| Aplazada | Media (5.3) | 0.33% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Alta (7.1) | 0.22% | — | Cmsmasters Content ComposerAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8. | |
| Aplazada | Media (6.4) | 0.21% | — | Masterstudylms LMSAI | 14/2/2026 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Crítica (9.3) | 1.3% | — | Airleader MasterAI | 12/2/2026 | 17/6/2026 | Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server. | |
| Analizada | Media (6.1) | 0.32% | — | Yottamaster DM2 FirmwareYottamaster DM3 FirmwareYottamaster Dm200 Firmware | 3/2/2026 | 17/6/2026 | An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the internal file system.… | |
| Analizada | Crítica (9.5) | 0.86% | — | Asustor Data Master | 3/2/2026 | 17/6/2026 | When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI program allowing an unauthenticated remote attacker to write arbitrary data to any file on the system. By exploiting this vulnerability, attackers can overwrite critical… | |
| Analizada | Media (6.3) | 0.16% | — | Asustor Data Master | 3/2/2026 | 17/6/2026 | A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device services requires additional authentication, a Man-in-the-Middle (MitM) attacker can intercept or redirect the NAT tunnel establishment. This could allow an attacker to… | |
| Analizada | Media (6.3) | 0.17% | — | Asustor Data Master | 3/2/2026 | 17/6/2026 | The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an external server for the device's WAN IP address. An unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to spoof the response, leading the device to update its DDNS record with an… | |
| Analizada | Alta (8.9) | 0.22% | — | Asustor Data Master | 3/2/2026 | 17/6/2026 | The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validation vulnerability allows an unauthenticated remote attacker can perform a Man-in-the-Middle (MitM) attack to intercept the cleartext communication, potentially leading to… | |
| Analizada | Alta (8.9) | 0.22% | — | Asustor Data Master | 3/2/2026 | 17/6/2026 | The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS, an improper validated TLS/SSL certificates allows a remote attacker can intercept the communication to perform a Man-in-the-Middle (MitM) attack, which may obtain the… |