Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.81% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands.… | |
| Analizada | Media (6.1) | 0.24% | — | SAP Business Connector | 11/11/2025 | 17/6/2026 | Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of… | |
| Aplazada | Alta (8.8) | 0.17% | — | Mongodb BI Connector Odbc DriverAI | 23/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Crmperks Connector FOR Gravity Forms AND Google SheetsAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Object Injection.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Selloio Sello ChannelconnectorAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in selloio Sello ChannelConnector sello-channelconnector allows Reflected XSS.This issue affects Sello ChannelConnector: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Never5 Post ConnectorAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barry Kooij Post Connector post-connector allows Reflected XSS.This issue affects Post Connector: from n/a through <= 1.0.11. | |
| Aplazada | Baja (2.4) | 0.15% | — | Gsheetconnector FOR Gravity FormsAI | 11/10/2025 | 17/6/2026 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to trick authenticated… | |
| Aplazada | Alta (8.8) | 0.43% | — | Gsheetconnector FOR Gravity FormsAI | 11/10/2025 | 30/9/2026 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'install_plugin' function. This makes it possible for authenticated attackers, with subscriber-level access and above to install… | |
| Aplazada | Alta (8.8) | 0.12% | — | Mongodb Connector FOR BIAI | 8/10/2025 | 17/6/2026 | MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24. | |
| Aplazada | Media (5.4) | 0.23% | — | Crowdstrike ConnectorAI | 7/10/2025 | 17/6/2026 | Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access. | |
| Aplazada | Alta (7.2) | 0.64% | — | Raoinfotech Gsheets Connector SheetlinkAI | 22/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This issue affects GSheets Connector: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | Beyondcart ConnectorAI | 11/9/2025 | 30/9/2026 | The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity. | |
| Modificada | Alta (7.2) | 1.2% | 💥 PoC | Celonis Make Connector | 4/9/2025 | 17/6/2026 | The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions up to, and including, 1.5.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files… | |
| Aplazada | Media (5.4) | 0.14% | — | Crmperks Connector FOR Gravity Forms AND Google SheetsAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Cross Site Request Forgery.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4. | |
| Aplazada | Media (4.7) | 0.26% | — | Crmperks Connector FOR Gravity Forms AND Google SheetsAI | 14/8/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Phishing.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4. | |
| Aplazada | Baja (3.5) | 0.46% | — | SAP Cloud ConnectorAI | 12/8/2025 | 17/6/2026 | Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful exploit could lead to reduced performance, hence a low-impact on availability of the service.… | |
| Analizada | Media (6.8) | 0.36% | — | Tesla Wall Connector Firmware | 30/7/2025 | 17/6/2026 | Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware upgrade feature.… | |
| Analizada | Alta (8.8) | 0.32% | — | Tesla Wall Connector Firmware | 30/7/2025 | 17/6/2026 | Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Crítica (10) | 68% | ⚠ Explotación activa | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Media (4.1) | 0.42% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to improper enforcement of access controls that are configured… | |
| Analizada | Alta (7.2) | 19% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this… | |
| Analizada | Alta (7.2) | 9.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this… | |
| Aplazada | Media (4.3) | 0.14% | — | Westerndeal Woocommerce Google Sheet ConnectorAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WesternDeal WooCommerce Google Sheet Connector wc-gsheetconnector allows Cross Site Request Forgery.This issue affects WooCommerce Google Sheet Connector: from n/a through <= 1.3.20. | |
| Analizada | Media (6.7) | 0.19% | — | Cisco Spaces Connector | 2/7/2025 | 17/6/2026 | A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient restrictions during the execution of specific CLI commands. An attacker could exploit this… | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. |