Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
814 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.32% | — | TablemasterAI | 28/1/2026 | 17/6/2026 | The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.6. This is due to the plugin not restricting which URLs can be fetched when importing CSV data from a URL in the Data Table widget. This makes it possible for authenticated… | |
| Aplazada | Media (6.7) | 0.29% | — | Agatasoft Pingmaster PROAI | 23/1/2026 | 17/6/2026 | AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in the Trace Route feature that allows attackers to crash the application by overflowing the host name input field. Attackers can generate a 10,000-character buffer and paste it into the host name field to trigger an application crash and… | |
| Aplazada | Media (4.3) | 0.22% | — | Ludwig YOU WpmastertoolkitAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPMasterToolKit: from n/a through <= 2.14.0. | |
| Aplazada | Media (4.3) | 0.18% | — | Expresstechsystems Quiz AND Survey MasterAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Frank Corso Quote MasterAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frank Corso Quote Master quote-master allows Reflected XSS.This issue affects Quote Master: from n/a through <= 7.1.1. | |
| Aplazada | Alta (8.5) | 0.15% | — | Coolmaster MasterplusAI | 13/1/2026 | 17/6/2026 | CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot. | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR Objectscale*Progress ECS Connection ManagerProgress LoadmasterProgress Moveit WAF+1 | 13/1/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Hypervisor+1 | 13/1/2026 | 10/8/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Aplazada | Crítica (9.3) | 0.33% | — | Imaster Mems Events CRMAI | 12/1/2026 | 17/6/2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. | |
| Aplazada | Alta (8.7) | 0.29% | — | Imaster Mems Events CRMAI | 12/1/2026 | 17/6/2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’. | |
| Aplazada | Alta (8.7) | 0.29% | — | Imaster Patient Records Management SystemAI | 12/1/2026 | 17/6/2026 | Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’ parameter. | |
| Aplazada | Media (5.1) | 0.27% | — | Imaster Patient Record Management SystemAI | 12/1/2026 | 17/6/2026 | Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/projects/hospital/admin/edit_patient.php’. By injecting a malicious script into the ‘firstname’ parameter, the JavaScript code is stored and executed every time a user accesses the patient list,… | |
| Aplazada | Media (6.1) | 0.37% | — | Testimonial MasterAI | 7/1/2026 | 17/6/2026 | The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.4) | 0.17% | — | Stylemixthemes Masterstudy LMSAI | 6/1/2026 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.5) | 0.27% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view… | |
| Analizada | Media (6.5) | 0.26% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Media (4.3) | 0.22% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.24% | — | Jeweltheme Master Addons FOR ElementorAI | 31/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4. | |
| Aplazada | Media (6.5) | 0.37% | — | Jeweltheme Master Addons FOR ElementorAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Master Addons for Elementor: from n/a through 2.0.5.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Masteriyo - LMSAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.5) | 0.36% | — | Stylemixthemes Masterstudy LMS PROAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16. | |
| Aplazada | Alta (7.5) | 0.36% | — | Stylemixthemes Masterstudy LMS PROAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16. | |
| Aplazada | Alta (7.5) | 0.34% | — | Stylemixthemes MasterstudyAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy: from n/a through < 4.8.122. | |
| Aplazada | Media (5.3) | 0.46% | — | WpmasteroolkitAI | 12/12/2025 | 17/6/2026 | The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin allowing Author-level users to create and execute arbitrary PHP code through the Code Snippets feature without proper capability checks. This makes it possible for… | |
| Analizada | Alta (7) | 0.10% | — | Asustor Data Master | 12/12/2025 | 17/6/2026 | When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification can allow an attacker able to intercept network traffic between the client and server can perform a man-in-the-middle (MITM) attack, which may obtain the sensitive information of the UPS server… |