Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.20% | — | MD Taufiqur Rahman RIS Version SwitcherAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Md Taufiqur Rahman RIS Version Switcher – Downgrade or Upgrade WP Versions Easily ris-version-switcher allows Cross Site Request Forgery.This issue affects RIS Version Switcher – Downgrade or Upgrade WP Versions Easily: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Admin IN English With SwitchAI | 11/9/2025 | 17/6/2026 | The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the enable_eng function. This makes it possible for unauthenticated attackers to modify administrator language settings… | |
| Aplazada | Alta (7.1) | 0.23% | — | Undoit Theme Switcher ReloadedAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undoIT Theme Switcher Reloaded theme-switcher-reloaded allows Reflected XSS.This issue affects Theme Switcher Reloaded: from n/a through <= 1.1. | |
| Aplazada | Media (5) | 0.35% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAICisco Nx-osAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS)… | |
| Aplazada | Alta (7.5) | 0.67% | — | UI Edgemax EdgeswitchAI | 21/8/2025 | 17/6/2026 | An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network. Affected Products: EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) Mitigation: Update the EdgeMAX EdgeSwitch to Version 1.11.1 or later. | |
| Aplazada | Alta (7.1) | 0.23% | — | Webilop User Language SwitchAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilop User Language Switch user-language-switch allows Reflected XSS.This issue affects User Language Switch: from n/a through <= 1.6.10. | |
| Modificada | Alta (8.1) | 0.59% | — | Fortinet FortiswitchmanagerFortinet FortiproxyFortinet FortipamFortinet Fortios | 12/8/2025 | 17/6/2026 | An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through… | |
| Aplazada | Alta (7) | 0.15% | — | Intel Pcie Switch FirmwareAIIntel LED Mode Toggle ToolAI | 12/8/2025 | 17/6/2026 | Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.5) | 0.58% | — | UI Edgemax EdgeswitchAI | 4/8/2025 | 17/6/2026 | An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network. | |
| Aplazada | Media (5.9) | 0.15% | — | SwitchbotAIApple IOSAIGoogle AndroidAI | 29/7/2025 | 17/6/2026 | "SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs. | |
| Aplazada | Alta (8.6) | 0.19% | — | ABB Switch Actuator 4 Du-83330AIABB Switch Actuator Door Light 4 Du-83330-500AI | 22/7/2025 | 17/6/2026 | : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions. | |
| Aplazada | Alta (7.1) | 0.13% | — | Vgstef WP User Stylesheet SwitcherAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows Stored XSS.This issue affects WP User Stylesheet Switcher: from n/a through <= v2.2.0. | |
| Analizada | Media (5) | 0.13% | — | Samsung Smart Switch | 4/6/2025 | 17/6/2026 | Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.2) | 0.94% | — | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortios | 28/5/2025 | 17/6/2026 | A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication… | |
| Aplazada | Alta (8.7) | 1.0% | — | Command Center LCD KVM Over IP Switch Cl5708imAI | 9/5/2025 | 17/6/2026 | The LCD KVM over IP Switch CL5708IM has a Heap-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to perform a denial-of-service attack. | |
| Aplazada | Alta (8.3) | 0.34% | — | Cisco IOS SoftwareAICisco Industrial Ethernet Switch Device ManagerAI | 7/5/2025 | 17/6/2026 | A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending… | |
| Modificada | Media (5.4) | 0.22% | — | Plugin-planet Theme Switcha | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from n/a through <= 3.4. | |
| Aplazada | Media (6.4) | 0.32% | — | TAX Switch FOR WoocommerceAI | 22/4/2025 | 17/6/2026 | The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ parameter in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Analizada | Crítica (9.8) | 16% | 💥 PoC | Fortinet Fortiswitch | 8/4/2025 | 17/6/2026 | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request | |
| Aplazada | Media (5.9) | 0.26% | — | Vasilis Triantafyllou Flag IconsAIVasilis Triantafyllou Language-icons-flags-switcherAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vasilis Triantafyllou Flag Icons language-icons-flags-switcher allows Stored XSS.This issue affects Flag Icons: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpwham Currency Switcher FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce currency-switcher-for-woocommerce allows Stored XSS.This issue affects Currency Switcher for WooCommerce: from n/a through <= 0.0.7. | |
| Analizada | Crítica (9.8) | 18% | 💥 PoC | Fortinet FortiwebFortinet FortiswitchmanagerFortinet FortiswitchFortinet Fortiproxy+4 | 24/3/2025 | 17/6/2026 | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below… | |
| Aplazada | Alta (7.1) | 0.39% | — | Catchthemes Catch Duplicate SwitcherAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Catch Duplicate Switcher catch-duplicate-switcher allows Reflected XSS.This issue affects Catch Duplicate Switcher: from n/a through <= 2.0. | |
| Aplazada | Media (6.1) | 0.35% | — | Wpwham Currency Switcher FOR WoocommerceAI | 1/3/2025 | 17/6/2026 | The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.16.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (6.7) | 0.24% | — | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortiproxyFortinet Fortipam | 11/2/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests. |