Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.29% | — | ScalenutAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Scalenut Scalenut scalenut allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scalenut: from n/a through <= 1.1.5. | |
| Aplazada | Media (5.4) | 0.21% | — | Theeventscalendar THE Events CalendarAI | 20/1/2026 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level… | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR Objectscale*Progress ECS Connection ManagerProgress LoadmasterProgress Moveit WAF+1 | 13/1/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Hypervisor+1 | 13/1/2026 | 10/8/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Media (5.3) | 0.30% | — | Siemens Gridscale X Prepay | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establish still valid user sessions. | |
| Analizada | Media (6.9) | 0.46% | — | Siemens Gridscale X Prepay | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users. | |
| Analizada | Crítica (9.4) | 62% | ⚠ Explotación activa💥 Exploit | Anyscale RAY | 26/11/2025 | 1/10/2026 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent… | |
| Aplazada | Media (5.2) | 0.12% | — | Zscaler Client ConnectorAI | 12/11/2025 | 17/6/2026 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls. | |
| Aplazada | Media (5.9) | 25% | 💥 Exploit | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 11/11/2025 | 17/6/2026 | Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Alta (7.5) | 0.18% | — | Dell Powerscale Onefs | 10/11/2025 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Aplazada | Alta (7.5) | 0.27% | — | Redhat 3scale Developer PortalAI | 6/11/2025 | 17/6/2026 | A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information. | |
| Aplazada | Media (5.3) | 0.27% | — | Theeventscalendar THE Events CalendarAI | 5/11/2025 | 17/6/2026 | The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report… | |
| Aplazada | Alta (7.5) | 18% | — | Theeventscalendar THE Events CalendarAI | 5/11/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append… | |
| Aplazada | Media (4.3) | 0.24% | — | Theeventscalendar THE Events CalendarAI | 31/10/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event… | |
| Analizada | Media (4.4) | 0.13% | — | Dell Powerscale Onefs | 8/10/2025 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain unauthorized access to NFSv4 or SMB shares. | |
| Aplazada | Media (6.6) | 0.13% | — | AMD Zynq Ultrascale PlusAI | 6/10/2025 | 17/6/2026 | In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality. | |
| Analizada | Alta (7.5) | 0.41% | — | Dell Powerscale Onefs | 25/9/2025 | 17/6/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | |
| Aplazada | Media (5.3) | 0.83% | 💥 Exploit | Theeventscalendar THE Events CalendarAI | 16/9/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues. | |
| Aplazada | Alta (7.5) | 0.35% | — | Theeventscalendar THE Events CalendarAI | 12/9/2025 | 25/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Media (6.7) | 0.13% | — | Dell Powerscale Onefs | 8/9/2025 | 17/6/2026 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Media (6.9) | 0.11% | — | Tomtretbar Dell Powerscale | 28/8/2025 | 25/9/2026 | Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic. | |
| Aplazada | Alta (8.7) | 3.3% | — | Citrix Netscaler ADCAICitrix Netscaler GatewayAI | 26/8/2025 | 17/6/2026 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access | |
| Analizada | Alta (8.8) | 8.2% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it | |
| Analizada | Crítica (9.2) | 20% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB… | |
| Aplazada | Crítica (9.6) | 0.40% | — | Zscaler Saml AuthenticationAI | 5/8/2025 | 17/6/2026 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. |