Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 6.5% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper… | |
| Analizada | Crítica (9.9) | 10% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (6) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This… | |
| Analizada | Media (5.3) | 0.18% | — | Zscaler Client Connector | 31/3/2026 | 24/7/2026 | An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances. | |
| Aplazada | Media (5.3) | 0.68% | 💥 Exploit | LeadconnectorAI | 26/3/2026 | 17/6/2026 | The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data | |
| Aplazada | Media (4.3) | 0.19% | — | Neos Connector FOR FakturamaAI | 21/3/2026 | 17/6/2026 | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_plugin_page() function which handles settings updates. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Crítica (9.9) | 0.38% | — | Westerndeal Gsheetconnector-wpformsAI | 20/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Code Injection.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Varunvairavanlc LeadconnectorAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LeadConnector: from n/a through <= 3.0.21. | |
| Analizada | Media (6.6) | 0.58% | — | Smn2gnt MCP Salesforce Connector | 6/2/2026 | 17/6/2026 | MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.1.10, arbitrary attribute access leads to disclosure of Salesforce auth token. This vulnerability is fixed in 0.1.10. | |
| Aplazada | Alta (8.4) | 0.16% | — | Eset Inspect ConnectorAI | 30/1/2026 | 17/6/2026 | Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL. | |
| Aplazada | Media (5.3) | 0.25% | — | Apimo ConnectorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Proptech Plugin Apimo Connector apimo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apimo Connector: from n/a through <= 2.6.5.2. | |
| Aplazada | Media (6.5) | 0.37% | — | Renatoatshown Shown ConnectorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in renatoatshown Shown Connector shown-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shown Connector: from n/a through <= 1.2.10. | |
| Aplazada | Crítica (10) | 0.52% | — | Modular DS Modular-connectorAI | 16/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0. | |
| Aplazada | Alta (7.7) | 0.41% | — | Apache KafkaAIGoogle BigqueryAIAiven Google Bigquery Kafka Connect Sink ConnectorAI | 16/1/2026 | 17/6/2026 | Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink connector requires Google Cloud credential configurations for authentication to… | |
| Aplazada | Crítica (9.8) | 22% | 💥 Exploit | Modular DS Modular ConnectorAI | 14/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1. | |
| Analizada | Media (6.1) | 0.20% | — | SAP Business Connector | 13/1/2026 | 17/6/2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious link. When an unsuspecting user clicks this link, the user may be redirected to a site controlled by the attacker. Successful exploitation could allow the attacker to access or modify… | |
| Aplazada | Media (4.9) | 6.2% | — | Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI | 7/1/2026 | 17/6/2026 | This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the… | |
| Aplazada | Media (5.3) | 0.25% | — | Westerndeal Gsheetconnector-wpformsAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.0. | |
| Aplazada | Media (4.3) | 0.20% | — | Gsheetconnector FOR Ninja FormsAI | 22/11/2025 | 17/6/2026 | The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.29% | — | Bigbuy Dropshipping ConnectorAI | 21/11/2025 | 17/6/2026 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Media (5.2) | 0.12% | — | Zscaler Client ConnectorAI | 12/11/2025 | 17/6/2026 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls. | |
| Analizada | Media (6.8) | 0.28% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system commands on the… | |
| Analizada | Media (6.1) | 0.23% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensitive information and… |