Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.30% | — | Miniflux Project Miniflux | 8/1/2026 | 17/6/2026 | Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen media URLs embedded in… | |
| Analizada | Media (5.5) | 0.57% | — | 1234n Minicms | 5/1/2026 | 7/10/2026 | A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may… | |
| Analizada | Media (5.5) | 0.57% | — | 1234n Minicms | 5/1/2026 | 7/10/2026 | A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.44% | — | 1234n Minicms | 5/1/2026 | 7/10/2026 | A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.69% | — | 1234n Minicms | 5/1/2026 | 7/10/2026 | A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be… | |
| Modificada | Crítica (9.3) | 1.4% | — | Minidvblinux | 30/12/2025 | 17/6/2026 | MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access. | |
| Aplazada | Media (6.6) | 0.48% | — | Miniorange Wordpress Social Login AND RegisterAI | 30/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.7.0. | |
| Modificada | Media (5.1) | 0.18% | — | Teradek Vidiu PRO FirmwareTeradek Vidiu FirmwareTeradek Vidiu Mini Firmware | 24/12/2025 | 17/6/2026 | Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious web pages that automatically submit password change requests to the device when a logged-in administrator visits the page. | |
| Modificada | Media (6.9) | 0.33% | — | Teradek Vidiu PRO FirmwareTeradek Vidiu FirmwareTeradek Vidiu Mini Firmware | 24/12/2025 | 17/6/2026 | Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary… | |
| Aplazada | Media (5.4) | 0.25% | — | Wpadminify WP AdminifyAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1. | |
| Aplazada | Media (4.3) | 0.23% | — | Wpadminify WP AdminifyAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1. | |
| Modificada | Alta (8.1) | 0.50% | — | Thememove Minimogwp | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6. | |
| Aplazada | Media (6.5) | 0.31% | — | Miniorange 2 Factor AuthenticationAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects miniOrange's Google Authenticator: from n/a through <= 6.1.1. | |
| Analizada | Alta (7.8) | 0.20% | — | Miniconda3 | 17/12/2025 | 17/6/2026 | Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading… | |
| Aplazada | Media (6.9) | 0.39% | — | Guralp Fortimus SeriesAIGuralp Minimus SeriesAIGuralp Certimus SeriesAI | 16/12/2025 | 17/6/2026 | A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with network access to send specially-crafted HTTP requests that can cause the web service process to deliberately restart. Although this mechanism limits the impact of the attack,… | |
| Analizada | Alta (7.5) | 0.36% | — | Thememove Minimogwp | 16/12/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6. | |
| Aplazada | Alta (8.7) | 0.49% | — | MinialicAI | 11/12/2025 | 17/6/2026 | minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending oversized GET requests. Attackers can send crafted HTTP requests with excessive data to overwhelm the server and cause service interruption. | |
| Analizada | Media (5.3) | 0.22% | — | Miniflux Project Miniflux | 11/12/2025 | 17/6/2026 | Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-relative URLs like //ikotaslabs.com have an empty scheme and pass that check, allowing post-login redirects to attacker-controlled sites.… | |
| Analizada | Media (6.9) | 0.92% | — | Minidvblinux | 9/12/2025 | 17/6/2026 | MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV systems. Attackers can send crafted SVDRP commands through the svdrpsend.sh script to execute messages and potentially control the video disk recorder remotely. | |
| Analizada | Alta (8.7) | 0.53% | — | Minidvblinux | 9/12/2025 | 17/6/2026 | MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without… | |
| Analizada | Alta (8.7) | 0.96% | — | Minidvblinux | 9/12/2025 | 17/6/2026 | MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device. | |
| Analizada | Crítica (9.3) | 0.97% | — | Minidvblinux | 9/12/2025 | 17/6/2026 | MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PASSWORD parameters to reset root credentials. | |
| Analizada | Alta (8.7) | 0.54% | — | Minidvblinux | 9/12/2025 | 17/6/2026 | MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete… | |
| Aplazada | Baja (2.1) | 0.23% | — | Jihai Jshop Miniprogram Mall SystemAI | 8/12/2025 | 17/6/2026 | A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functionality of the file /index.php/api.html. The manipulation of the argument cat_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. The… | |
| Aplazada | Media (6.4) | 0.18% | — | Surbma Minicrm ShortcodeAI | 21/11/2025 | 17/6/2026 | The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'minicrm' shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… |