Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

4214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)1.6%💥 ExploitHippoo Mobile APP FOR WoocommerceAI11/6/202617/6/2026
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
AnalizadaAlta (8.1)0.65%—Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack10/6/20265/8/2026
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that…
AplazadaCrítica (9.8)2.9%💥 ExploitHippoo Mobile APP FOR WoocommerceAI5/6/202617/6/2026
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both…
AplazadaAlta (8.8)0.42%—Kurt Software Studio Writeup Mobile APPAI4/6/202622/7/2026
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
AnalizadaMedia (5.3)0.24%—Netapp Active IQ Onecollect3/6/202622/7/2026
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
AnalizadaMedia (5.3)0.24%—Netapp Active IQ Config Advisor3/6/202622/7/2026
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
AnalizadaAlta (8.5)0.68%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
AnalizadaCrítica (9)0.62%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
AnalizadaCrítica (9)0.64%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
AnalizadaCrítica (9.1)0.47%—IBM Websphere Application Server1/6/202622/7/2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
AplazadaAlta (8.8)0.43%—Frontier X Mobile ApplicationAISeil X2AI29/5/202622/7/2026
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,…
AplazadaMedia (5.3)0.64%—Booking Calendar Simply Schedule AppointmentsAI28/5/202617/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.…
ModificadaMedia (5.9)0.30%—IBM Websphere Application Server27/5/202617/6/2026
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
AnalizadaAlta (7.5)0.69%—IBM Websphere Application Server27/5/202617/6/2026
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to…
AplazadaMedia (5.3)0.44%—Simply Schedule AppointmentsAI27/5/202623/7/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied…
AnalizadaCrítica (9.8)0.94%—IBM Websphere Application Server26/5/202623/7/2026
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
AnalizadaAlta (7.5)0.37%—IBM Websphere Application Server26/5/202623/7/2026
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.
AplazadaMedia (6.3)0.18%—Turkiye Electricity Transmission Corporation Mobile ApplicationAI21/5/202623/7/2026
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13.
AplazadaMedia (5.7)0.18%—Turkiye Electricity Transmission Corporation Mobile ApplicationAI21/5/202623/7/2026
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13.
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaBaja (2.9)0.57%💥 PoCCodewise Tornet Scooter Mobile APPAI3/5/202617/6/2026
A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. Attacks of this nature are highly…
AnalizadaMedia (5.9)0.37%—IBM Websphere Application Server23/4/202617/6/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
AplazadaMedia (6.3)0.25%—Honor E APPAI21/4/202617/6/2026
Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.
AnalizadaBaja (2.3)0.18%—Netapp Storagegrid20/4/20268/7/2026
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
AplazadaMedia (5.3)0.26%—Nsquared Simply Schedule AppointmentsAI8/4/202624/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.