Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
930 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 2.4% | — | Moussaabbadla Code-screenshot-mcpAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor… | |
| Analizada | Media (6.9) | 0.27% | — | Zabbix | 24/3/2026 | 10/9/2026 | An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time. | |
| Analizada | Alta (8.7) | 3.9% | 💥 PoC | Zabbix | 24/3/2026 | 10/9/2026 | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based… | |
| Analizada | Alta (7.7) | 0.30% | — | Zabbix | 24/3/2026 | 10/9/2026 | Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands. | |
| Analizada | Media (6.1) | 0.23% | — | Zabbix | 24/3/2026 | 18/9/2026 | Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API. | |
| Analizada | Alta (7.1) | 0.24% | — | Zabbix | 24/3/2026 | 18/9/2026 | For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the… | |
| Aplazada | Alta (7.2) | 0.29% | — | ABB Awin Gw100AIABB Awin Gw120AI | 13/3/2026 | 17/6/2026 | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1. | |
| Aplazada | Alta (7.1) | 0.27% | — | ABB Awin Gw100AIABB Awin Gw120AI | 13/3/2026 | 17/6/2026 | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1. | |
| Aplazada | Alta (7.2) | 0.23% | — | ABB Awin Gw100AIABB Awin Gw120AI | 13/3/2026 | 17/6/2026 | Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1. | |
| Analizada | Media (5.1) | 0.26% | — | Zabbix | 6/3/2026 | 17/6/2026 | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write… | |
| Aplazada | Alta (8.1) | 0.34% | — | Themerex BlabberAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Blabber blabber allows PHP Local File Inclusion.This issue affects Blabber: from n/a through <= 1.7.0. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6420 FirmwareQualcomm Qca6430 FirmwareQualcomm Qcc2072 Firmware+33 | 2/2/2026 | 17/6/2026 | Memory Corruption when multiple threads simultaneously access a memory free API. | |
| Aplazada | Media (5.4) | 0.19% | — | Softlabbd Radio PlayerAI | 23/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.91. | |
| Aplazada | Media (5.4) | 0.26% | — | Softlabbd Integrate Google DriveAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.5.6. | |
| Aplazada | Alta (7.5) | 0.35% | — | Tabbyai Tabby CheckoutAI | 22/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in tabbyai Tabby Checkout tabby-checkout allows Retrieve Embedded Sensitive Data.This issue affects Tabby Checkout: from n/a through <= 5.8.4. | |
| Aplazada | Crítica (9.2) | 0.44% | — | ABB Ability OptimaxAI | 16/1/2026 | 17/6/2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120. | |
| Aplazada | Alta (8.4) | 0.17% | — | Youtube Video Grabber Youtube DownloaderAI | 15/1/2026 | 17/6/2026 | YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious payload of 712 bytes with SEH manipulation to trigger a bind shell connection… | |
| Aplazada | Alta (7.1) | 0.21% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Aplazada | Alta (8.4) | 0.27% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Aplazada | Alta (7.1) | 0.21% | — | ABB Webpro Snmp Card PowervalueAIABB Webpro Snmp Card Powervalue ULAI | 7/1/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove UngrabberAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnGrabber: from n/a through <= 3.1.3. | |
| Modificada | Media (5.1) | 0.28% | — | Phpjabbers Simple CMS | 17/12/2025 | 17/6/2026 | PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling… | |
| Analizada | Alta (8.7) | 0.61% | — | Phpjabbers Simple CMS | 17/12/2025 | 17/6/2026 | PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information. | |
| Analizada | Crítica (9.3) | 0.45% | — | Phpjabbers BUS Reservation System | 15/12/2025 | 17/6/2026 | Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database. | |
| Aplazada | Media (4.3) | 0.15% | — | Rabbit HoleAI | 12/12/2025 | 17/6/2026 | The Rabbit Hole plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the plugin's reset functionality. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request… |