Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.34% | — | Edimax Ew-7438rpn Mini Firmware | 5/2/2026 | 17/6/2026 | Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges. | |
| Analizada | Crítica (9.3) | 7.1% | — | Edimax Ew-7438rpn Mini Firmware | 5/2/2026 | 17/6/2026 | Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious… | |
| Aplazada | Alta (8.8) | 0.17% | — | Mitsubishi Electric Corporation Freqship-miniAI | 5/2/2026 | 17/6/2026 | Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing service executable files (EXE) or DLLs in the installation directory with specially crafted files. As a… | |
| Analizada | Alta (8.7) | 0.45% | — | Edimax Ew-7438rpn Mini Firmware | 3/2/2026 | 17/6/2026 | Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables. | |
| Analizada | Media (5.1) | 0.17% | — | Edimax Ew-7438rpn Mini Firmware | 3/2/2026 | 17/6/2026 | Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent. | |
| Aplazada | Baja (1.3) | 0.41% | — | DJI Mavic MiniAIDJI Mavic AIRAIDJI SparkAIDJI Mavic Mini SEAI | 2/2/2026 | 17/6/2026 | A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be carried out from within the local network.… | |
| Aplazada | Alta (7.1) | 0.23% | — | Mini-stream RM DownloaderAI | 30/1/2026 | 17/6/2026 | RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload with an egg hunter technique to bypass memory protections and execute commands like launching calc.exe. | |
| Aplazada | Crítica (9.2) | 5.5% | 💥 Exploit | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… | |
| Analizada | Media (5.4) | 0.18% | — | Salsa.digital Mini Site | 28/1/2026 | 17/6/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpadminify WP AdminifyAI | 28/1/2026 | 17/6/2026 | The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/adminify/v1/get-addons-list REST API endpoint. The endpoint is registered with permission_callback set to __return_true, allowing unauthenticated attackers to retrieve the… | |
| Aplazada | Media (4.4) | 0.28% | — | Order Minimum Maximum Amount Limits FOR WoocommerceAI | 28/1/2026 | 17/6/2026 | The Order Minimum/Maximum Amount Limits for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level… | |
| Aplazada | Alta (8.5) | 0.19% | — | Minitool ShadowmakerAI | 26/1/2026 | 17/6/2026 | MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges. | |
| Aplazada | Media (4.6) | 0.17% | — | Kaba 9300 AdministrationAI | 26/1/2026 | 17/6/2026 | The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation. | |
| Aplazada | Alta (7.5) | 0.76% | — | Administrative ShortcodesAI | 24/1/2026 | 17/6/2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' attribute of the 'get_template' shortcode. This is due to insufficient path validation on user-supplied input passed to the get_template_part() function. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | Administrative ShortcodesAI | 24/1/2026 | 17/6/2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'login' and 'logout' shortcode attributes in all versions up to, and including, 0.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.8) | 0.33% | — | Svenstaro Miniserve | 23/1/2026 | 17/6/2026 | A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared… | |
| Aplazada | Media (5.3) | 0.26% | — | Passionatebrains ADD Expires Headers AND Optimized MinifyAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Expires Headers & Optimized Minify: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.8) | 3.5% | — | Gemini-mcp-toolAI | 23/1/2026 | 17/6/2026 | gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of gemini-mcp-tool. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the… | |
| Aplazada | Media (5.4) | 0.11% | — | Launchinteractive Merge Minify RefreshAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14. | |
| Analizada | Crítica (9.3) | 1.2% | — | Yodinfo Mini Mouse | 21/1/2026 | 17/6/2026 | Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script commands. | |
| Analizada | Alta (8.7) | 1.4% | — | Yodinfo Mini Mouse | 21/1/2026 | 17/6/2026 | Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path… | |
| Analizada | Alta (8.7) | 0.74% | — | Yodinfo Mini Mouse | 21/1/2026 | 17/6/2026 | Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests. | |
| Analizada | Media (5.4) | 0.27% | — | Eachitaly Wireless Mini Router Wireless-n 300m Firmware | 15/1/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to execute arbitrary scripts via a crafted payload due to unsanitized repeater AP SSID value when is displayed in any page at /index.htm. | |
| Aplazada | Alta (8.6) | 0.48% | — | Google GeminiAI | 14/1/2026 | 15/7/2026 | External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with… | |
| Aplazada | Media (5.3) | 0.27% | — | Miniorange OTP Verification SMS NotificationAI | 10/1/2026 | 17/6/2026 | The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unauthenticated… |