Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

21.079 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.47%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
AnalizadaAlta (7.5)0.37%—UI Unifi Talk Application2/7/20269/7/2026
A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.
AnalizadaAlta (8.7)0.59%—UI Unifi Network Application2/7/20266/7/2026
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.
AnalizadaAlta (7.5)0.52%—UI Unifi Network Application2/7/20262/7/2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.
AnalizadaCrítica (9.9)0.49%—UI Unifi Talk Application2/7/20269/7/2026
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
AnalizadaCrítica (10)1.7%💥 PoCUI Unifi Connect Application2/7/202629/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
AplazadaAlta (7.7)0.80%—Openwrt Luci-app-travelmateAIOpenwrt TravelmateAI2/7/202628/8/2026
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only…
AplazadaMedia (4.6)0.23%—TR7 Cyber Defense INC WEB Application FirewallAI2/7/20262/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.
AplazadaMedia (5.3)0.52%—WappointmentAI2/7/20262/7/2026
The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointment `edit_key` — the sole authorization token consumed by `tryCancel()` — being…
AplazadaAlta (7.6)0.28%—Tinacms APPAISSW TinacmsAI1/7/20262/7/2026
Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass enable stored XSS and session takeover. The library registers window message listeners — the useTina overlay handler, the OAuth…
AnalizadaAlta (7.7)0.73%—Amazon Advanced Jdbc Wrapper1/7/20269/7/2026
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java…
AplazadaMedia (5.3)0.29%—WP Reloaded ApplyonlineAI1/7/20261/7/2026
Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.
AplazadaMedia (6.5)0.45%—Motopress Appointment BookingAI1/7/20261/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (7.5)0.46%—Bookingpress Appointment Booking PROAI1/7/20261/7/2026
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is…
AplazadaMedia (4.3)0.39%—Appointment Booking CalendarAI1/7/20261/7/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email…
ModificadaCrítica (9.8)0.42%—IBM Websphere Application Server30/6/202629/7/2026
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
AnalizadaMedia (6.1)0.34%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.
ModificadaMedia (5.5)0.27%—IBM APP Connect EnterpriseIBM Integration BUS30/6/202620/7/2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
AnalizadaAlta (7.5)0.47%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
ModificadaCrítica (9.8)0.36%—IBM Websphere Application Server30/6/20266/8/2026
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.
AnalizadaCrítica (9.3)0.38%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system.
AnalizadaAlta (7.5)0.78%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integrated help system.
AnalizadaCrítica (9.8)0.40%—IBM Websphere Application Server30/6/20262/7/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
Pendiente de análisisAlta (7.3)0.14%—HP FAN Control APPAI30/6/20262/7/2026
—