Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
9665 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.09% | — | Huawei EmuiHuawei Harmonyos | 28/11/2025 | 17/6/2026 | Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | |
| Aplazada | Media (5.3) | 0.26% | — | Quick View FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Aplazada | Media (4.3) | 0.15% | — | Opinionstage Poll Survey Quiz MakerAI | 27/11/2025 | 17/6/2026 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers… | |
| Modificada | Alta (7.7) | 0.32% | — | Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+25 | 26/11/2025 | 31/8/2026 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,… | |
| Analizada | Crítica (9.8) | 0.61% | 💥 PoC | Apache Druid | 26/11/2025 | 17/6/2026 | El autenticador Kerberos de Apache Druid utiliza un secreto de respaldo débil cuando la configuración `druid.auth.authenticator.kerberos.cookieSignatureSecret` no se establece explícitamente. En este caso, el secreto se genera utilizando `ThreadLocalRandom`, que no es un generador de números aleatorios… | |
| Aplazada | Alta (7.6) | 0.29% | — | Nvidia Nemo Agent Toolkit UI FOR WEBAI | 25/11/2025 | 17/6/2026 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service. | |
| Aplazada | Media (5.3) | 0.26% | — | ACE Post Type BuilderAI | 25/11/2025 | 17/6/2026 | The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing authorization validation on the cptb_delete_custom_taxonomy() function in all versions up to, and including, 1.9. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Crítica (9.3) | 0.62% | — | Ruijie NBRAI | 24/11/2025 | 17/6/2026 | Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or… | |
| Aplazada | Media (6.5) | 0.20% | — | Funnelkit Funnel BuilderAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows DOM-Based XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.13.1.2. | |
| Aplazada | Media (6.5) | 0.19% | — | Bold-themes Bold Page BuilderAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2. | |
| Aplazada | Media (4.3) | 0.22% | — | Uipress LiteAI | 21/11/2025 | 7/10/2026 | El plugin UiPress lite | Effortless custom dashboards, admin themes and pages para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de capacidad en la función uip_save_site_option() en todas las versiones hasta, e incluyendo, la 3.5.08. Esto hace posible que atacantes… | |
| Aplazada | Media (6.4) | 0.21% | — | Uipress LiteAI | 21/11/2025 | 7/10/2026 | El plugin UiPress lite | Paneles personalizados sin esfuerzo, temas de administración y páginas para WordPress es vulnerable a la modificación no autorizada de datos debido a una comprobación de capacidad faltante en la función 'uip_save_ui_template' en todas las versiones hasta la 3.5.08, inclusive. Esto hace posible… | |
| Aplazada | Media (6.5) | 0.25% | — | Uipress LiteAI | 21/11/2025 | 7/10/2026 | El plugin UiPress lite para WordPress es vulnerable a la exposición de información sensible en todas las versiones hasta la 3.5.08, inclusive. Esto se debe a la falta de comprobaciones de capacidad en la función AJAX 'uip_process_block_query'. Esto permite a atacantes autenticados, con acceso de nivel suscriptor y… | |
| Aplazada | Media (6.4) | 0.18% | — | Coatedmedia User Profile BuilderAI | 19/11/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.4) | 0.24% | — | Funnelkit Funnel Builder FOR Woocommerce CheckoutAI | 19/11/2025 | 17/6/2026 | The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up to, and including, 3.13.1.2. This is due to insufficient input sanitization and output escaping on the user-supplied `default` attribute. This… | |
| Analizada | Alta (7.5) | 0.33% | — | Ays-pro Quiz Maker | 19/11/2025 | 17/6/2026 | The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.7.0.80. This is due to the plugin exposing quiz answers through the ays_quiz_check_answer AJAX action without proper authorization checks. The endpoint only validates a nonce, but that same nonce… | |
| Aplazada | Media (5.5) | 0.33% | — | Shsuishang ShopsuiteAI | 16/11/2025 | 17/6/2026 | A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.41% | — | Shsuishang ShopsuiteAI | 16/11/2025 | 17/6/2026 | A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path traversal. It is possible to… | |
| Analizada | Media (6.9) | 0.27% | — | Opensolution Quick.cms | 14/11/2025 | 7/10/2026 | Una vulnerabilidad existe en QuickCMS versión 6.8 donde las credenciales de administrador sensibles están codificadas de forma rígida en un archivo de configuración y almacenadas en texto plano. Esta falla permite a los atacantes con acceso al código fuente o al sistema de archivos del servidor recuperar los detalles… | |
| Analizada | Media (4.8) | 0.18% | — | Opensolution Quick.cms | 14/11/2025 | 7/10/2026 | QuickCMS es vulnerable a múltiples XSS Almacenados en la funcionalidad del editor de idiomas (languages). Atacante malicioso con privilegios de administrador puede inyectar HTML y JS arbitrarios en el sitio web, que se renderizará/ejecutará en cada página. Por defecto, el usuario administrador no puede añadir… | |
| Aplazada | Media (5.3) | 0.26% | — | Crocoblock JetformbuilderAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en jetmonsters JetFormBuilder jetformbuilder permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a JetFormBuilder: desde n/a hasta menor o igual que 3.5.3. | |
| Aplazada | Media (4.3) | 0.19% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de falta de autorización en EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a WooCommerce PDF Invoice Builder: desde n/a hasta menor o igual que 1.2.150. | |
| Aplazada | Media (4.3) | 0.20% | — | QuicqAI | 13/11/2025 | 7/10/2026 | El plugin Convert WebP & AVIF | Quicq | Best image optimizer and compression | Improve your Google Pagespeed para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de capacidad en el endpoint AJAX 'wp_ajax_wpqai_disconnect_quicq_afosto' en todas las versiones hasta la… | |
| Analizada | Media (5.4) | 0.20% | — | Ph7builder PH7 Social Dating Builder | 12/11/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted by the server and later rendered in another user's Inbox view without appropriate context-aware encoding. As a result,… | |
| Aplazada | Alta (8.6) | 0.74% | — | Ucancode E-xd++ Visualization Enterprise SuiteAI | 12/11/2025 | 17/6/2026 | UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to… |