Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
21.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.47% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | |
| Analizada | Alta (7.5) | 0.37% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints. | |
| Analizada | Alta (8.7) | 0.59% | — | UI Unifi Network Application | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device. | |
| Analizada | Alta (7.5) | 0.52% | — | UI Unifi Network Application | 2/7/2026 | 2/7/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application. | |
| Analizada | Crítica (9.9) | 0.49% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. | |
| Analizada | Crítica (10) | 1.7% | 💥 PoC | UI Unifi Connect Application | 2/7/2026 | 29/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. | |
| Aplazada | Alta (7.7) | 0.80% | — | Openwrt Luci-app-travelmateAIOpenwrt TravelmateAI | 2/7/2026 | 28/8/2026 | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only… | |
| Aplazada | Media (4.6) | 0.23% | — | TR7 Cyber Defense INC WEB Application FirewallAI | 2/7/2026 | 2/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117. | |
| Aplazada | Media (5.3) | 0.52% | — | WappointmentAI | 2/7/2026 | 2/7/2026 | The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointment `edit_key` — the sole authorization token consumed by `tryCancel()` — being… | |
| Aplazada | Alta (7.6) | 0.28% | — | Tinacms APPAISSW TinacmsAI | 1/7/2026 | 2/7/2026 | Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass enable stored XSS and session takeover. The library registers window message listeners — the useTina overlay handler, the OAuth… | |
| Analizada | Alta (7.7) | 0.73% | — | Amazon Advanced Jdbc Wrapper | 1/7/2026 | 9/7/2026 | Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java… | |
| Aplazada | Media (5.3) | 0.29% | — | WP Reloaded ApplyonlineAI | 1/7/2026 | 1/7/2026 | Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6. | |
| Aplazada | Media (6.5) | 0.45% | — | Motopress Appointment BookingAI | 1/7/2026 | 1/7/2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.46% | — | Bookingpress Appointment Booking PROAI | 1/7/2026 | 1/7/2026 | The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is… | |
| Aplazada | Media (4.3) | 0.39% | — | Appointment Booking CalendarAI | 1/7/2026 | 1/7/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email… | |
| Modificada | Crítica (9.8) | 0.42% | — | IBM Websphere Application Server | 30/6/2026 | 29/7/2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability. | |
| Analizada | Media (6.1) | 0.34% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. | |
| Modificada | Media (5.5) | 0.27% | — | IBM APP Connect EnterpriseIBM Integration BUS | 30/6/2026 | 20/7/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of. | |
| Analizada | Alta (7.5) | 0.47% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled. | |
| Modificada | Crítica (9.8) | 0.36% | — | IBM Websphere Application Server | 30/6/2026 | 6/8/2026 | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. | |
| Analizada | Alta (7.5) | 0.78% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system. | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Websphere Application Server | 30/6/2026 | 2/7/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled. | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | HP FAN Control APPAI | 30/6/2026 | 2/7/2026 | — |