Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 4.5% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 21/1/2026 | 17/6/2026 | — | |
| Aplazada | Media (5.3) | 0.27% | — | Community EventsAI | 17/1/2026 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events via the 'eventlist'… | |
| Aplazada | Baja (2) | 0.22% | — | Cloudpanel Community EditionAI | 30/12/2025 | 7/10/2026 | A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (5.3) | 0.29% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI | 15/12/2025 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. | |
| Aplazada | Alta (8.8) | 0.43% | — | Pentaho Data IntegrationAIPentaho Analytics Community Dashboard EditorAI | 15/12/2025 | 17/6/2026 | Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods. | |
| Modificada | Media (5.5) | 0.14% | — | Redhat Community.general | 4/12/2025 | 17/6/2026 | A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise… | |
| Aplazada | Media (4.3) | 0.18% | — | Shahjahan Jewel Fluent-communityAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentCommunity: from n/a through <= 2.0.0. | |
| Aplazada | Alta (7.5) | 0.32% | — | Community EventsAI | 19/11/2025 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Media (6.1) | 0.20% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields. | |
| Analizada | Crítica (9.8) | 0.45% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials. | |
| Analizada | Crítica (9.8) | 0.35% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field. | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | React-native-community React Native Community CLI | 3/11/2025 | 17/6/2026 | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On… | |
| Aplazada | Alta (7.2) | 0.29% | — | Community EventsAI | 1/11/2025 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (7.8) | 0.50% | — | Dell Unity Operating Environment | 30/10/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 30/10/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.69% | — | Dell Unity Operating Environment | 30/10/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability… | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 30/10/2025 | 17/6/2026 | Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 30/10/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.50% | — | Dell Unity Operating Environment | 30/10/2025 | 30/9/2026 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Community EventsAI | 9/10/2025 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Community EventsAI | 8/10/2025 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Analizada | Alta (7.4) | 0.59% | 💥 PoC | Unity Editor | 3/10/2025 | 17/6/2026 | Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code… | |
| Aplazada | Media (4.3) | 0.33% | — | Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI | 18/9/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600… | |
| Aplazada | Crítica (10) | 0.64% | — | Saurus CMS Community EditionAI | 19/8/2025 | 5/7/2026 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP code execution. | |
| Aplazada | Alta (7.3) | 0.27% | — | Unity Business Technology PTY LTD THE E-commerce ERPAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3. |