Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.47% | — | Getgrav GravAIGetgrav Admin2AI | 18/6/2026 | 22/6/2026 | Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow. | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Dell Openmanage Integration FOR Microsoft Windows Admin CenterAIMicrosoft Windows Admin CenterAI | 16/6/2026 | 1/10/2026 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The malicious user may gain the ability to run arbitrary code remotely. This is a high… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Boruta WEBAIBoruta IdentityAIBoruta AdminAI | 11/6/2026 | 17/6/2026 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the identity “remember me” cookie were set without the Secure attribute. In deployments where users could reach the same Boruta… | |
| Aplazada | Media (4.3) | 0.37% | 💥 PoC | SqladminAI | 10/6/2026 | 23/7/2026 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpoints enforce. If a developer restricts model access by overriding is_accessible(), an authenticated user can still… | |
| Aplazada | Media (5.4) | 0.23% | — | FastapiadminAI | 9/6/2026 | 23/7/2026 | A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a chat message. | |
| Aplazada | Media (6.1) | 0.25% | — | FastapiadminAI | 9/6/2026 | 23/7/2026 | A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the notice_content parameter. | |
| Aplazada | Media (6.5) | 0.41% | — | FastapiadminAI | 9/6/2026 | 23/7/2026 | An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) via manipulating the func field of scheduled tasks. | |
| Aplazada | Baja (2) | 0.22% | — | Dcatadmin Dcat-adminAI | 9/6/2026 | 23/7/2026 | A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument editormd-image-file causes unrestricted upload. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (6.9) | 0.34% | — | Admin Word Count ColumnAI | 8/6/2026 | 23/7/2026 | WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing directory traversal… | |
| Aplazada | Alta (8.8) | 1.2% | 💥 PoC | Admincolumns Admin ColumnsAI | 5/6/2026 | 23/7/2026 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which processes… | |
| Aplazada | Crítica (9.1) | 1.1% | — | Cluster-admin Backup-datastoreAI | 5/6/2026 | 17/6/2026 | An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request. | |
| Aplazada | Baja (2.1) | 1.1% | — | EladminAI | 2/6/2026 | 22/7/2026 | A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manipulation of the argument uploadPath causes command injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Media (4.9) | 0.29% | — | Dynamiapps Frontend AdminAI | 29/5/2026 | 21/7/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.3) | 0.49% | — | Sourcebans Material AdminAI | 28/5/2026 | 17/6/2026 | An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file. | |
| Aplazada | Alta (7.3) | 0.42% | — | Sourcebans Material AdminAI | 28/5/2026 | 17/6/2026 | An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call. | |
| Aplazada | Alta (8.8) | 1.2% | — | Dynamiapps Frontend AdminAI | 28/5/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When… | |
| Aplazada | Alta (8.8) | 0.75% | — | Dynamiapps Frontend AdminAI | 28/5/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (8.8) | 0.50% | — | Kvf-adminAI | 27/5/2026 | 17/6/2026 | Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component | |
| Aplazada | Media (4.3) | 0.27% | — | Wp-media AdminimizeAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11. | |
| Aplazada | Media (6.3) | 0.13% | 💥 PoC | Jason2605 AdminpanelAI | 27/5/2026 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0. | |
| Modificada | Alta (7.8) | 0.37% | — | Microsoft Windows Admin Center | 20/5/2026 | 23/7/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.2) | 0.28% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available. | |
| Aplazada | Media (5.4) | 0.23% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user. | |
| Aplazada | Alta (8.8) | 0.77% | — | Dynamiapps Frontend AdminAI | 15/5/2026 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post… | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Windows Admin Center | 12/5/2026 | 17/6/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |