Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.78% | — | Linux PAM AccessAI | 7/11/2024 | 31/8/2026 | A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who… | |
| Aplazada | Media (6.5) | 0.49% | — | Creativemotion Titan Anti-spam SecurityAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6. | |
| Modificada | Media (4.7) | 0.27% | — | Linux-pam | 23/10/2024 | 30/6/2026 | A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in… | |
| Aplazada | Media (6.1) | 0.39% | — | Kama SpamblockAI | 16/10/2024 | 17/6/2026 | The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Aplazada | Crítica (9.1) | 0.45% | — | C-chip CchipamaotaAI | 11/10/2024 | 5/7/2026 | An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Aplazada | Media (5.3) | 0.34% | — | Limit Login Attempts Spam ProtectionAI | 8/10/2024 | 17/6/2026 | The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the… | |
| Analizada | Media (5.3) | 0.35% | — | Wpcerber Cerber Security Antispam & Malware Scan | 31/8/2024 | 17/6/2026 | The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been blocked to bypass this control by setting the X-Forwarded-For: HTTP… | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Phpipam | 29/8/2024 | 17/6/2026 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 28/8/2024 | 17/6/2026 | Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option. | |
| Analizada | Alta (8.8) | 0.44% | — | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosFortinet Fortipam | 13/8/2024 | 17/6/2026 | An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions… | |
| Aplazada | Media (5.3) | 0.44% | — | Wpamelia AmeliaAI | 8/8/2024 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve… | |
| Analizada | Alta (7.1) | 0.33% | — | Phpipam | 26/7/2024 | 17/6/2026 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php | |
| Analizada | Alta (7.1) | 0.34% | — | Phpipam | 26/7/2024 | 17/6/2026 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php | |
| Analizada | Alta (7.1) | 1.1% | 💥 Exploit | Phpipam | 26/7/2024 | 17/6/2026 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. | |
| Analizada | Media (4.7) | 0.44% | — | Phpipam | 26/7/2024 | 17/6/2026 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php. | |
| Modificada | Media (6.5) | 0.38% | — | Phpipam | 26/7/2024 | 17/6/2026 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php. | |
| Aplazada | Media (5.1) | 0.25% | — | Linux PAMAI | 15/7/2024 | 17/6/2026 | The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships. | |
| Aplazada | Alta (8.6) | 0.61% | — | PAMAI | 15/7/2024 | 17/6/2026 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request. | |
| Aplazada | Baja (3.2) | 0.28% | — | CockpitAILinux-pam PAM ENVAI | 3/7/2024 | 17/6/2026 | A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack. | |
| Analizada | Alta (7.5) | 0.79% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager | 11/6/2024 | 17/6/2026 | A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0… | |
| Aplazada | Media (5.3) | 0.35% | — | Yonifre Maspik Spam BlacklistAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in yonifre Maspik – Spam blacklist allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maspik – Spam blacklist: from n/a through 0.10.3. | |
| Aplazada | Media (5.3) | 0.37% | — | Pluginkollektiv Antispam BEEAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: from n/a through 2.11.3. | |
| Analizada | Media (4.6) | 1.3% | — | Zohocorp Manageengine Pam360 | 29/5/2024 | 17/6/2026 | Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610. | |
| Analizada | Alta (8.1) | 0.90% | — | Zohocorp Manageengine Pam360 | 20/5/2024 | 17/6/2026 | Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability. | |
| Aplazada | Media (5.3) | 0.35% | — | Highfivery LLC Zero SpamAI | 17/5/2024 | 17/6/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6. |