Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.38% | — | Motopress Timetable AND Event ScheduleAI | 28/5/2026 | 17/6/2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Hackerbay OneuptimeAI | 27/5/2026 | 17/6/2026 | OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not designed for that and can be escaped via error objects and infinite recursion. This vulnerability is fixed in 10.0.98. | |
| Aplazada | Alta (7.5) | 0.52% | — | Revmakx Backup AND Staging BY WP Time CapsuleAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25. | |
| Pendiente de análisis | Media (5.3) | 0.60% | — | Outsystems LifetimeAI | 25/5/2026 | 11/8/2026 | OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID parameter. Any authenticated user, can read the Change Log containing actions performed by other users as well as application name of any application. This issue was fixed in OutSystems Lifetime version… | |
| Aplazada | Media (6.9) | 0.23% | — | Mybb Timeline PluginAI | 16/5/2026 | 17/6/2026 | MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change… | |
| Aplazada | Media (5.1) | 0.21% | — | PHP TimeclockAI | 15/5/2026 | 17/6/2026 | PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers can append malicious payloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, or inject code through… | |
| Aplazada | Alta (8.8) | 0.27% | — | PHP TimeclockAI | 15/5/2026 | 17/6/2026 | PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE conditional statements… | |
| Modificada | Media (5.9) | 0.58% | — | Bytecodealliance Wasmtime | 14/5/2026 | 28/7/2026 | Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible… | |
| Aplazada | Alta (8.2) | 0.34% | — | Arraytics TimeticsAI | 12/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53. | |
| Aplazada | Media (5.1) | 0.22% | — | 3dady Real Time WEB StatsAI | 10/5/2026 | 23/9/2026 | WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin… | |
| Aplazada | Alta (7.4) | 0.80% | — | Iptime A8004tAI | 10/5/2026 | 24/7/2026 | A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.4) | 0.27% | — | Openjsf MarkoOpenjsf Marko/runtime-tags | 8/5/2026 | 26/8/2026 | Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is interpolated into a <script> or <style> tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase casing. An attacker able… | |
| Analizada | Media (5.8) | 0.38% | — | Solidtime | 8/5/2026 | 17/6/2026 | solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all in the URL organization, allowing a known foreign time-entry UUID to be… | |
| Rechazada | Sin puntuar | — | — | Mendix RuntimeAI | 7/5/2026 | 22/9/2026 | Rejected reason: This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. | |
| Analizada | Alta (7.7) | 0.81% | — | Redistimeseries | 5/5/2026 | 25/7/2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can… | |
| Aplazada | Alta (8.9) | 1.0% | — | Iptime Nas1dualAI | 5/5/2026 | 17/6/2026 | A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The… | |
| Aplazada | Alta (7.3) | 4.4% | — | Iptime C200AI | 5/5/2026 | 17/6/2026 | A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component ApplyRestore Endpoint. This manipulation of the argument RestoreFile causes command injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.65% | — | Ruvnet Sublinear-time-solverAI | 2/5/2026 | 17/6/2026 | A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. The manipulation results in path traversal. The attack can be executed remotely. The exploit has been made… | |
| Analizada | Media (4.8) | 0.18% | — | Draugiemgroup Desktime Time Tracking | 28/4/2026 | 7/10/2026 | Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve… | |
| Aplazada | Media (6.4) | 0.35% | — | Timeline BlocksAI | 28/4/2026 | 17/6/2026 | The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Media (5.5) | 0.11% | — | Linuxfoundation Sigstore Timestamp Authority | 15/4/2026 | 17/6/2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certificate chain signature, but the TSA-specific constraint checks in VerifyLeafCert… | |
| Pendiente de análisis | Crítica (9.8) | 0.92% | — | Talend JobserverAITalend RuntimeAI | 14/4/2026 | 17/6/2026 | A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend JobServer by requiring TLS client authentication for the… | |
| Analizada | Media (6.1) | 0.26% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's realloc is not validated before the host attempts to write through the pointer. This enables a guest to… | |
| Analizada | Media (6.1) | 0.37% | — | Bytecodealliance Wasmtime | 9/4/2026 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For 32-bit tables this means that the result of the operator, internally in Winch, is tagged as… |