Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.42% | — | Rachel Cherry Lock Your UpdatesAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates lock-your-updates allows Reflected XSS.This issue affects Lock Your Updates: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.17% | — | Ashokbasnet Nepali-date-utilitiesAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ashokbasnet Nepali Date Utilities nepali-date-utilities allows Stored XSS.This issue affects Nepali Date Utilities: from n/a through <= 1.0.15. | |
| Analizada | Alta (7.8) | 1.1% | — | Microsoft Autoupdate | 8/4/2025 | 17/6/2026 | Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 1.1% | — | Microsoft Autoupdate | 8/4/2025 | 17/6/2026 | Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (8.8) | 0.39% | — | Email Notifications FOR UpdatesAI | 5/4/2025 | 17/6/2026 | The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.9) | 0.32% | — | Bitdefender Gravityzone Update Server | 4/4/2025 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing null-byte (%00) sequences. By crafting a… | |
| Modificada | Alta (7.4) | 14% | — | Gnome YelpDebian LinuxRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64+17 | 3/4/2025 | 29/6/2026 | A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. | |
| Aplazada | Alta (7.1) | 0.29% | — | David Wood Latest Custom Post Type UpdatesAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest Custom Post Type Updates latest-custom-post-type-updates allows Reflected XSS.This issue affects Latest Custom Post Type Updates: from n/a through <= 1.3.0. | |
| Modificada | Media (6.5) | 0.86% | — | Gnome LibsoupRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR Arm64 EUS+17 | 3/4/2025 | 30/6/2026 | A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. | |
| Aplazada | Media (6.5) | 0.26% | — | Denra WP Date AND Time ShortcodeAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Denra.com WP Date and Time Shortcode wp-date-and-time-shortcode allows Stored XSS.This issue affects WP Date and Time Shortcode: from n/a through <= 2.6.7. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft Edge Update | 23/3/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (4.3) | 0.17% | — | Fastmover Plugins Last Updated ColumnAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column plugins-last-updated-column allows Cross Site Request Forgery.This issue affects Plugins Last Updated Column: from n/a through <= 0.1.3. | |
| Modificada | Alta (8.8) | 0.19% | — | Venugopal Comment Date AND Gravatar Remover | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0. | |
| Modificada | Media (6.1) | 0.15% | — | Bhzad WP Jquery Persian Datepicker | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery Persian Datepicker: from n/a through <= 0.1.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Devu Status UpdaterAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devu Status Updater fb-status-updater allows Reflected XSS.This issue affects Status Updater: from n/a through <= 1.9.2. | |
| Aplazada | Media (6.5) | 0.37% | — | Codingkart WOO Update Variations IN CartAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codingkart Woo Update Variations In Cart woo-update-variations-in-cart allows Stored XSS.This issue affects Woo Update Variations In Cart: from n/a through <= 0.0.9. | |
| Aplazada | Alta (7.1) | 0.28% | — | Michael Stursberg Browser-update-notifyAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Stursberg Browser-Update-Notify browser-update-notify allows Reflected XSS.This issue affects Browser-Update-Notify: from n/a through <= 0.2.1. | |
| Analizada | Alta (7.8) | 0.16% | — | Mongodb MongoshRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+9 | 27/2/2025 | 17/6/2026 | mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0 | |
| Analizada | Alta (7.8) | 0.15% | — | Mongodb CompassRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux Server FOR Power Little Endian Update Services FOR SAP Solutions+1 | 27/2/2025 | 17/6/2026 | MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1 | |
| Analizada | Crítica (9.8) | 0.64% | — | Keesiemeijer Custom Post Type Date Archives | 22/2/2025 | 17/6/2026 | The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Analizada | Media (4.3) | 0.17% | — | Exeebit Disable Auto Updates | 19/2/2025 | 17/6/2026 | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged… | |
| Aplazada | Alta (7.1) | 0.31% | — | Rusalex Wordpress-to-candidate FOR Salesforce CRMAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RusAlex WordPress-to-candidate for Salesforce CRM salesforce-wordpress-to-candidate allows Reflected XSS.This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.19% | — | Intel Server M50fcp Bios AND System Firmware Update PackageAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft Autoupdate | 11/2/2025 | 17/6/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Analizada | Media (5.4) | 0.19% | — | Dell Update Manager Plugin | 7/2/2025 | 17/6/2026 | Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |