Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.2) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is EV SoC update with powermeter periodic update and unplugging/SessionFinished status. Version 2026.02.0 patches the issue. | |
| Analizada | Media (4.2) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurrent access. with heap-use-after-free possible. This is triggered by EVCCID update (EV/ISO15118) and OCPP session/authorization events. Version 2026.02.0 contains a patch. | |
| Analizada | Media (4.2) | 0.15% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is an EV SoC update with powermeter periodic update and unplugging/SessionFinished state. Version 2026.2.0 contains a patch. | |
| Analizada | Alta (7.5) | 0.46% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch. | |
| Analizada | Alta (7.8) | 0.21% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling potential code execution. A malicious or… | |
| Analizada | Alta (8.8) | 0.53% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from… | |
| Analizada | Alta (7.8) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-based buffer overflow when a filename length equals `MAX_FILE_NAME_LENGTH` (100). A crafted filename in the certificate directory can overflow `file_names[idx]`, corrupting… | |
| Analizada | Alta (8.8) | 0.47% | — | Wecodex Restaurant CMS | 26/3/2026 | 17/6/2026 | Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind… | |
| Aplazada | Alta (7.5) | 0.39% | — | Stellarwp Restrict ContentAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/a through <= 3.2.22. | |
| Aplazada | Alta (8.1) | 0.37% | 💥 PoC | Wpeverest User RegistrationAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through <= 4.4.9. | |
| Aplazada | Alta (7.1) | 0.18% | — | Acato WP Rest CacheAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acato WP REST Cache wp-rest-cache allows Stored XSS.This issue affects WP REST Cache: from n/a through <= 2026.1.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Rustaurius Five Star Restaurant ReservationsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | E4jvikwp VikrestaurantsAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5.2. | |
| Aplazada | Media (5.3) | 0.44% | — | Rest API TO MiniprogramAI | 21/3/2026 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter corresponds to an existing… | |
| Aplazada | Media (4.3) | 0.34% | — | Restrictcontent Membership Plugin Restrict ContentAI | 20/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpeverest Everest Forms PROAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.This issue affects Everest Forms Pro: from n/a through 1.9.10. | |
| Aplazada | Media (6.4) | 0.23% | — | Riverforest-wp Simple Blog CardAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Side Request Forgery.This issue affects Simple Blog Card: from n/a through <= 2.37. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Restaurant AND CafeAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Restaurant and Cafe restaurant-and-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant and Cafe: from n/a through <= 1.2.5. | |
| Aplazada | Media (6.3) | 0.25% | — | Streamsoft PrestizAI | 12/3/2026 | 17/6/2026 | Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92. | |
| Aplazada | Alta (8.1) | 0.36% | — | Membershipupplugin Membership Plugin Restrict ContentAI | 5/3/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active… | |
| Analizada | Media (4.9) | 0.35% | — | Suse Rancher Backup AND Restore Operator | 4/3/2026 | 17/6/2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. | |
| Analizada | Alta (7.3) | 0.15% | — | Synology Presto Client | 24/2/2026 | 17/6/2026 | An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and conduct denial-of-service during installation by placing a malicious DLL in advance in the same directory as the installer. | |
| Analizada | Baja (2) | 0.36% | — | Rymcu Forest | 22/2/2026 | 17/6/2026 | A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit… | |
| Analizada | Baja (2) | 0.36% | — | Rymcu Forest | 22/2/2026 | 17/6/2026 | A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio. The manipulation leads to cross site scripting. Remote exploitation… | |
| Aplazada | Alta (7.1) | 0.19% | — | Zyxel PrestigeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Prestige prestige allows Reflected XSS.This issue affects Prestige: from n/a through < 1.4.1. |