Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

472 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.78%—Linux PAM AccessAI7/11/202431/8/2026
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who…
AplazadaMedia (6.5)0.49%—Creativemotion Titan Anti-spam SecurityAI1/11/202417/6/2026
Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6.
ModificadaMedia (4.7)0.27%—Linux-pam23/10/202430/6/2026
A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in…
AplazadaMedia (6.1)0.39%—Kama SpamblockAI16/10/202417/6/2026
The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if…
AplazadaCrítica (9.1)0.45%—C-chip CchipamaotaAI11/10/20245/7/2026
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.
AplazadaMedia (5.3)0.34%—Limit Login Attempts Spam ProtectionAI8/10/202417/6/2026
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the…
AnalizadaMedia (5.3)0.35%—Wpcerber Cerber Security Antispam & Malware Scan31/8/202417/6/2026
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP…
ModificadaMedia (6.1)1.6%💥 ExploitPhpipam29/8/202417/6/2026
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
AnalizadaAlta (8.8)3.0%—Zohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO28/8/202417/6/2026
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
AnalizadaAlta (8.8)0.44%—Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosFortinet Fortipam13/8/202417/6/2026
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions…
AplazadaMedia (5.3)0.44%—Wpamelia AmeliaAI8/8/202417/6/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve…
AnalizadaAlta (7.1)0.33%—Phpipam26/7/202417/6/2026
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
AnalizadaAlta (7.1)0.34%—Phpipam26/7/202417/6/2026
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
AnalizadaAlta (7.1)1.1%💥 ExploitPhpipam26/7/202417/6/2026
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
AnalizadaMedia (4.7)0.44%—Phpipam26/7/202417/6/2026
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
ModificadaMedia (6.5)0.38%—Phpipam26/7/202417/6/2026
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
AplazadaMedia (5.1)0.25%—Linux PAMAI15/7/202417/6/2026
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
AplazadaAlta (8.6)0.61%—PAMAI15/7/202417/6/2026
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
AplazadaBaja (3.2)0.28%—CockpitAILinux-pam PAM ENVAI3/7/202417/6/2026
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
AnalizadaAlta (7.5)0.79%—Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager11/6/202417/6/2026
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0…
AplazadaMedia (5.3)0.35%—Yonifre Maspik Spam BlacklistAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in yonifre Maspik – Spam blacklist allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maspik – Spam blacklist: from n/a through 0.10.3.
AplazadaMedia (5.3)0.37%—Pluginkollektiv Antispam BEEAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: from n/a through 2.11.3.
AnalizadaMedia (4.6)1.3%—Zohocorp Manageengine Pam36029/5/202417/6/2026
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.
AnalizadaAlta (8.1)0.90%—Zohocorp Manageengine Pam36020/5/202417/6/2026
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.
AplazadaMedia (5.3)0.35%—Highfivery LLC Zero SpamAI17/5/202417/6/2026
Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
Orbitaley — Vulnerabilidades