Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
9672 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.42% | — | Seatheme BM Content BuilderAI | 26/9/2025 | 30/9/2026 | Vulnerabilidad de limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de Ruta') en SeaTheme BM Content Builder permite el salto de ruta. Este problema afecta a BM Content Builder: desde n/a hasta n/a. | |
| Aplazada | Baja (2.7) | 0.22% | — | Shopengine Elementor Woocommerce Builder AddonAI | 26/9/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.5) | 0.37% | — | Dell Bsafe Micro-edition-suite | 25/9/2025 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Media (6.4) | 0.33% | — | Themify BuilderAI | 24/9/2025 | 25/9/2026 | El plugin Themify Builder para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de varios parámetros en todas las versiones hasta la 7.6.9, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto hace posible que atacantes autenticados, con acceso de nivel… | |
| Analizada | Media (5.4) | 0.25% | — | Ui-lib Stocky | 22/9/2025 | 17/6/2026 | Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulnerability within the Products module available to authenticated users. The vulnerability resides in the product name parameter submitted to the product-creation endpoint via a standard POST form. Due… | |
| Analizada | Media (4.8) | 0.24% | — | Liquidlabs Magicai | 22/9/2025 | 17/6/2026 | MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feature available to authenticated admin users. The vulnerability resides in the prompt parameter submitted to the /dashboard/user/generator/generate-stream endpoint via a multipart/form-data POST… | |
| Aplazada | Media (6.5) | 0.20% | — | Agency Dominion INC Fusion Page Builder Extension GalleryAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery fusion-extension-gallery allows Stored XSS.This issue affects Fusion Page Builder : Extension – Gallery: from n/a through <= 1.7.6. | |
| Aplazada | Media (4.3) | 0.14% | — | Tryinteract Interact Quiz EmbedAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tryinteract Interact: Embed A Quiz On Your Site interact-quiz-embed allows Cross Site Request Forgery.This issue affects Interact: Embed A Quiz On Your Site: from n/a through <= 3.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Guaven SQL Chart BuilderAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Guaven Labs SQL Chart Builder sql-chart-builder allows DOM-Based XSS.This issue affects SQL Chart Builder: from n/a through <= 2.3.7.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Shapedplugin LLC Quick View FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Quick View for WooCommerce woo-quickview allows Stored XSS.This issue affects Quick View for WooCommerce: from n/a through <= 2.2.16. | |
| Modificada | Alta (7.5) | 0.34% | — | Ays-pro Quiz Maker | 22/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-maker allows Retrieve Embedded Sensitive Data.This issue affects Quiz Maker: from n/a through <= 6.7.0.65. | |
| Modificada | Media (4.3) | 0.14% | — | Ays-pro Quiz Maker | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.64. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpbean WPB Quick View FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Quick View for WooCommerce woocommerce-lightbox allows Stored XSS.This issue affects WPB Quick View for WooCommerce: from n/a through <= 2.1.8. | |
| Aplazada | Media (5.4) | 0.17% | — | LOC BUI PayosAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Loc Bui payOS payos allows Cross Site Request Forgery.This issue affects payOS: from n/a through <= 1.0.73. | |
| Aplazada | Media (6.5) | 0.27% | — | HT Plugins HT Mega - Absolute Addons FOR Wpbakery Page BuilderAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows DOM-Based XSS.This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through <= 1.0.9. | |
| Aplazada | Baja (2) | 4.0% | — | Ruijie 6000-e10AI | 22/9/2025 | 17/6/2026 | A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument key causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.2) | 0.34% | — | Hyperx Ngenuity | 19/9/2025 | 17/6/2026 | HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerability. | |
| Aplazada | Media (5.4) | 0.27% | — | Kubio AI Page BuilderAI | 19/9/2025 | 17/6/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Baja (3.7) | 0.22% | — | Purevpn CLIAIPurevpn GUIAI | 18/9/2025 | 17/6/2026 | PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connected, but IPv6 traffic is no longer routed or blocked. In the GUI client, the IPv6… | |
| Aplazada | Alta (7.8) | 0.11% | — | Smartvista SuiteAI | 18/9/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request. | |
| Aplazada | Media (5.3) | 0.92% | 💥 Exploit | Kibokolabs Chained QuizAI | 18/9/2025 | 17/6/2026 | The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts… | |
| Analizada | Alta (7.5) | 0.94% | 💥 Exploit | Ays-pro Quiz Maker | 17/9/2025 | 17/6/2026 | The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.34% | — | Patika Global Technologies HumansuiteAI | 16/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Patika Global Technologies HumanSuite allows Cross-Site Scripting… | |
| Aplazada | Media (6.5) | 0.29% | — | Patika Global Technologies HumansuiteAI | 16/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerability in Patika Global Technologies HumanSuite allows Exploiting Trust in Client. This issue affects HumanSuite: before 53.21.0. | |
| Aplazada | Media (5.7) | 0.14% | — | GNU GuixAI | 15/9/2025 | 17/6/2026 | In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended). |