Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
9665 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.09% | — | Huawei EmuiHuawei Harmonyos | 8/12/2025 | 7/10/2026 | Vulnerabilidad de control de permisos en el módulo de gestión de ventanas. Impacto: La explotación exitosa de esta vulnerabilidad puede afectar la disponibilidad. | |
| Analizada | Media (5.5) | 0.09% | — | Huawei EmuiHuawei Harmonyos | 8/12/2025 | 7/10/2026 | Vulnerabilidad de control de permisos en el módulo de gestión de paquetes. Impacto: La explotación exitosa de esta vulnerabilidad puede afectar la confidencialidad del servicio. | |
| Analizada | Alta (8.9) | 0.52% | — | Aiql Tuui | 5/12/2025 | 25/9/2026 | TUUI es un cliente MCP de escritorio diseñado como una herramienta de integración de utilidad unitaria. Versiones anteriores a 1.3.4, existe una vulnerabilidad crítica de Ejecución Remota de Código (RCE) en Tuui debido a una falla insegura de Cross-Site Scripting (XSS) en el componente de renderizado de Markdown. Tuui… | |
| Aplazada | Media (5.5) | 0.30% | — | Trippwastaken PHP Guitar ShopAI | 5/12/2025 | 25/9/2026 | Se ha identificado una vulnerabilidad en TrippWasTaken PHP-Guitar-Shop hasta 6ce0868889617c1975982aae6df8e49555d0d555. Esta vulnerabilidad afecta código desconocido del archivo /product.php del componente Página de Detalles del Producto. La ejecución de la manipulación del argumento ID puede conducir a inyección SQL.… | |
| Analizada | Media (5.4) | 0.24% | — | Openwebui Open Webui | 4/12/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, allowing them to execute… | |
| Analizada | Alta (7.1) | 4.4% | — | Openwebui Open Webui | 4/12/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This can be exploited to access cloud metadata… | |
| Modificada | Media (4.3) | 0.28% | — | Openwebui Open Webui | 4/12/2025 | 17/6/2026 | open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks. | |
| Analizada | Alta (8.8) | 0.76% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ endpoints allow low-privilege users to upload ZIP files to the server. The plupload_file_upload function handles these file uploads and… | |
| Analizada | Alta (7.2) | 0.81% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application… | |
| Analizada | Alta (7.8) | 0.15% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the… | |
| Analizada | Crítica (9.8) | 0.39% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a… | |
| Analizada | Baja (2) | 0.41% | — | Xunruicms | 4/12/2025 | 17/6/2026 | Se ha encontrado una falla en dayrui XunRuiCMS hasta la versión 4.7.1. Esta vulnerabilidad afecta a código desconocido del archivo admin79f2ec220c7e.php?c=API&m=test_site_domain del componente Project Domain Change Test. Esta manipulación del argumento v causa falsificación de petición del lado del servidor. Es… | |
| Modificada | Baja (1.9) | 0.29% | — | Xunruicms | 4/12/2025 | 17/6/2026 | Se ha identificado una vulnerabilidad en dayrui XunRuiCMS hasta la versión 4.7.1. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=0 del componente 'Add Display Name Field'. La manipulación del argumento data[name]… | |
| Modificada | Baja (2) | 0.43% | — | Xunruicms | 4/12/2025 | 17/6/2026 | Se ha descubierto una vulnerabilidad de seguridad en dayrui XunRuiCMS hasta la versión 4.7.1. Afecta a una función desconocida del archivo /admind45f74adbd95.php?c=email&m=add del componente Email Setting Handler. Realizar una manipulación resulta en falsificación de petición del lado del servidor. La explotación… | |
| Analizada | Baja (1.1) | 0.27% | — | Xunruicms | 4/12/2025 | 25/9/2026 | Se detectó una vulnerabilidad en dayrui XunRuiCMS hasta la versión 4.7.1. Esto afecta una parte desconocida del archivo /admin79f2ec220c7e.php?c=api&m=demo&name=mobile del componente “Página de Enlace de Nombre de Dominio”. La manipulación resulta en cross-site scripting. El ataque puede realizarse de forma remota. Un… | |
| Analizada | Baja (2) | 0.27% | — | Xunruicms | 4/12/2025 | 25/9/2026 | Se ha detectado una vulnerabilidad de seguridad en dayrui XunRuiCMS hasta la versión 4.7.1. Afectada por este problema es alguna funcionalidad desconocida del archivo /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1 del componente “Add Data Validation Page”. La manipulación del argumento data[name] conduce… | |
| Aplazada | Media (4.8) | 0.30% | — | Webdevstudios Custom Post Type UIAI | 4/12/2025 | 17/6/2026 | The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.26% | — | Fastlinemedia Beaver Builder | 4/12/2025 | 17/6/2026 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is due to the plugin not properly verifying a user's authorization in the disable() function. This makes it possible for authenticated attackers, with contributor… | |
| Analizada | Crítica (9.8) | 0.47% | 💥 PoC | Anisha Online Medicine Guide | 2/12/2025 | 17/6/2026 | code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. | |
| Aplazada | Alta (8.6) | 0.27% | — | QuickcmsAI | 2/12/2025 | 17/6/2026 | A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable… | |
| Analizada | Media (4.3) | 0.31% | — | Fastlinemedia Beaver Builder | 2/12/2025 | 17/6/2026 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient capability checks in the REST API endpoints under the 'fl-controls/v1' namespace that control site-wide Global Presets. This makes it possible… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Form BuilderAI | 2/12/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenticated attackers to delete surveys via a… | |
| Aplazada | Alta (8.8) | 0.55% | — | Stylemixthemes Cost Calculator BuilderAI | 2/12/2025 | 17/6/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject arbitrary file paths into the orders that… | |
| Analizada | Alta (7.1) | 0.08% | — | Huawei EmuiHuawei Harmonyos | 28/11/2025 | 17/6/2026 | UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | |
| Analizada | Media (5.5) | 0.10% | — | Huawei EmuiHuawei Harmonyos | 28/11/2025 | 17/6/2026 | Vulnerabilidad de control de permisos en el módulo Settings. Impacto: la explotación con éxito de esta vulnerabilidad puede afectar a la confidencialidad del servicio. |