Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.0% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may… | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root… | |
| Analizada | Alta (7.8) | 0.58% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root… | |
| Aplazada | Media (5.4) | 0.19% | — | Immunity DebuggerAI | 17/3/2025 | 17/6/2026 | Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, due to the lack of proper boundary checking. | |
| Aplazada | Media (5.5) | 0.27% | — | Immunity INC Immunity DebuggerAI | 13/2/2025 | 17/6/2026 | A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size. | |
| Aplazada | Media (6.3) | 0.14% | — | OtrsAIOtrs Community EditionAI | 27/1/2025 | 17/6/2026 | Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Aplazada | Baja (3.5) | 0.22% | — | OtrsAIOtrs Community EditionAI | 27/1/2025 | 17/6/2026 | An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Aplazada | Media (6.9) | 0.58% | — | Hyland Alfresco Community EditionAIHyland Alfresco Enterprise EditionAI | 18/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.1) | 0.41% | — | Website Toolbox CommunityAI | 12/12/2024 | 17/6/2026 | The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolbox_username’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.1) | 0.56% | — | Community BY PeepsoAI | 21/11/2024 | 17/6/2026 | The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 7.0.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.38% | — | Michael Simpson Community Yard SaleAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale community-yard-sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through <= 1.1.11. | |
| Aplazada | Media (6.1) | 0.50% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAICisco Unified Communications Manager IM AND Presence ServiceAICisco Unity ConnectionAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker… | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Simple Music Cloud Community System | 10/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.4) | 0.28% | — | Community BY PeepsoAI | 16/10/2024 | 17/6/2026 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, and profiles when Markdown support is enabled in all versions up to, and including, 6.4.6.1 due to insufficient input… | |
| Modificada | Baja (2) | 0.52% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.3) | 0.69% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of the argument sitio leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.65% | — | Abcd-community Abcd | 4/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation of the argument image leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (8.2) | 0.38% | — | OtrsAIOtrs Community EditionAI | 26/8/2024 | 17/6/2026 | Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be… | |
| Aplazada | Media (4.9) | 0.36% | — | OtrsAIOtrs Community EditionAI | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: Products based on the ((OTRS)) Community… | |
| Analizada | Media (6.1) | 0.40% | — | Steve-community Steve | 12/8/2024 | 17/6/2026 | SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe… | |
| Analizada | Media (4.8) | 0.35% | — | Community Events Project Community Events | 5/8/2024 | 17/6/2026 | The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.26% | — | Community Events Project Community Events | 22/7/2024 | 17/6/2026 | The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack | |
| Analizada | Alta (8.1) | 0.40% | — | Oracle Trading Community | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks… | |
| Modificada | Crítica (9.8) | 8.7% | 💥 Exploit | Invisioncommunity | 7/6/2024 | 17/6/2026 | Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be… |