Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

930 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.17%—Handl UTM Grabber TrackerAI10/12/202525/9/2026
The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaAlta (7.1)0.17%—Handl UTM Grabber TrackerAI10/12/202525/9/2026
The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (6.1)0.26%—JabbernotificationAI5/12/202517/6/2026
The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.99-RC2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (5.9)0.12%—Zabbix AgentAIIBM AIXAI1/12/202517/6/2026
Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.
AnalizadaMedia (6)0.34%—Zabbix Frontend1/12/202525/9/2026
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
AnalizadaMedia (6.8)0.29%—Zabbix Frontend1/12/202525/9/2026
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
AplazadaMedia (6.9)0.20%—ABB Terra AC WallboxAI28/11/202517/6/2026
Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.
AplazadaCrítica (9.4)0.31%—ABB Ability EdgeniusAI20/11/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.
AplazadaMedia (6.9)0.21%—ABB Terra AC WallboxAI29/10/202517/6/2026
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.
ModificadaCrítica (9.8)0.58%—Axiomthemes White Rabbit22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This issue affects White Rabbit: from n/a through <= 1.5.2.
AplazadaMedia (6.1)0.28%—ABB Terra AC WallboxAI20/10/202517/6/2026
Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB Terra AC wallbox (MID/ CE) -Terra AC Juno CE, ABB Terra AC wallbox (MID/ CE) -Terra AC PTB, ABB Terra AC wallbox (JP).This issue affects Terra AC wallbox…
AplazadaAlta (8.2)0.19%—ABB Coresense HMAIABB Coresense M10AI20/10/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB CoreSense™ M10.This issue affects CoreSense™ HM: through 2.3.1; CoreSense™ M10: through 1.4.1.12.
AplazadaCrítica (9.9)0.77%—ABB Als-mini-s4 IPAIABB Als-mini-s8 IPAI20/10/202517/6/2026
Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . All firmware versions with the Serial Number from 2000 to 5166
AplazadaMedia (6.3)0.11%—Yt-grabber-tuiAI17/10/202517/6/2026
yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in the creation of the default configuration file config.json. In version 1.0, load_json_settings in Settings.hpp checks for…
AplazadaMedia (6.5)0.28%—WP Tabber WidgetAI15/10/202517/6/2026
The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all versions up to, and including, 4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AplazadaAlta (7.8)0.18%—YT Grabber TUIAIYt-dlp YT DLPAI13/10/202517/6/2026
yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure the path to the yt-dlp executable via the path_to_yt_dlp configuration setting. An attacker with write access to the configuration file or the filesystem location of the…
AplazadaMedia (5.7)0.10%—ABB MconfigAI8/10/202517/6/2026
Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.
AplazadaAlta (8.5)0.32%—ABB Eibport V3 KNXAIABB Eibport V3 KNX GSMAI7/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.
AnalizadaMedia (5.1)0.29%—Zabbix3/10/202517/6/2026
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.
AplazadaAlta (7.3)0.33%💥 PoCZabbix AgentAIZabbix Agent 2AI3/10/202517/6/2026
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
AnalizadaBaja (2.1)0.37%—Zabbix3/10/202517/6/2026
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
AnalizadaMedia (4.3)0.46%—Zabbix3/10/202517/6/2026
The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.
AplazadaMedia (6.9)0.21%—ABB Terra AC WallboxAI29/9/202517/6/2026
Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.
AnalizadaBaja (2.1)0.35%—Phpjabbers Restaurant Menu Maker23/9/202517/6/2026
A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and…
AplazadaAlta (8.5)0.37%—Wp-tabber-widgetAI22/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.com Wp tabber widget wp-tabber-widget allows SQL Injection.This issue affects Wp tabber widget: from n/a through <= 4.0.