Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.51% | — | Tencent PatrickstarAI | 23/12/2025 | 17/6/2026 | Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent PatrickStar. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.5) | 0.64% | — | Senstar SymphonyAI | 23/12/2025 | 17/6/2026 | Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Senstar Symphony. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of… | |
| Aplazada | Media (6.1) | 0.21% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 21/12/2025 | 17/6/2026 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Heartstar | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes HeartStar heartstar allows PHP Local File Inclusion.This issue affects HeartStar: from n/a through <= 1.0.14. | |
| Aplazada | Media (6.5) | 0.19% | — | Premio Stars TestimonialsAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Stars Testimonials stars-testimonials-with-slider-and-masonry-grid allows Stored XSS.This issue affects Stars Testimonials: from n/a through <= 3.3.4. | |
| Aplazada | Media (4.2) | 0.17% | 💥 PoC | Spacex Starlink DishAI | 11/12/2025 | 9/7/2026 | SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting a Referer header. In some cases, an attacker's ability to read tilt, rotation, and elevation data… | |
| Aplazada | Alta (8.8) | 14% | — | Starter TemplatesAI | 6/12/2025 | 17/6/2026 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Aplazada | Media (4.3) | 0.19% | — | ListarAI | 6/12/2025 | 17/6/2026 | The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/listar/v1/place/save' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.19% | — | ListarAI | 6/12/2025 | 17/6/2026 | The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '/wp-json/listar/v1/place/delete' REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.9) | 0.20% | — | Jeff Starr Head Meta DataAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Head Meta Data head-meta-data allows Stored XSS.This issue affects Head Meta Data: from n/a through <= 20250327. | |
| Analizada | Alta (8.4) | 0.15% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer. | |
| Analizada | Media (6.9) | 0.26% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. | |
| Analizada | Media (6.9) | 0.14% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed. | |
| Analizada | Media (5.3) | 0.23% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request. | |
| Analizada | Media (4.8) | 0.17% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page. | |
| Analizada | Media (6.8) | 0.12% | — | Secuavail Logstare Collector | 21/11/2025 | 17/6/2026 | The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege. | |
| Analizada | Alta (7.5) | 0.41% | — | Elcaradio Star150 FirmwareElcaradio Bp1000 FirmwareElcaradio Star300 FirmwareElcaradio Star2000 Firmware+2 | 19/11/2025 | 17/6/2026 | The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models, contains an information disclosure vulnerability allowing unauthenticated attackers to retrieve admin credentials and system settings via an unprotected /setup.xml endpoint. The… | |
| Aplazada | Media (5.4) | 0.17% | — | Saysis StarcitiesAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities allows Reflected XSS. This issue affects StarCities: before 1.1.61. | |
| Aplazada | Alta (8.4) | 0.14% | — | NEC Corporation Rakurakumusen Start EXAI | 19/11/2025 | 17/6/2026 | DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the user's device. | |
| Aplazada | Media (5.4) | 0.19% | — | SAP Starter SolutionAI | 11/11/2025 | 17/6/2026 | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low impact on the application's confidentiality and integrity but no impact on its availability. | |
| Modificada | Media (4.3) | 0.25% | — | Jenkins Start Windocks Container | 29/10/2025 | 17/6/2026 | A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |
| Modificada | Media (4.3) | 0.21% | — | Jenkins Start Windocks Container | 29/10/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL. | |
| Aplazada | Alta (7.5) | 0.68% | 💥 PoC | Encode StarletteAI | 28/10/2025 | 17/6/2026 | Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing… | |
| Aplazada | Alta (7.5) | 0.32% | — | Starcharge Artemis AC ChargerAI | 27/10/2025 | 17/6/2026 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens. | |
| Aplazada | Alta (8) | 0.29% | — | Starcharge Artemis AC ChargerAI | 27/10/2025 | 17/6/2026 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi. |