Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
932 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.35% | — | Phpjabbers Restaurant Menu Maker | 23/9/2025 | 17/6/2026 | A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Aplazada | Alta (8.5) | 0.37% | — | Wp-tabber-widgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.com Wp tabber widget wp-tabber-widget allows SQL Injection.This issue affects Wp tabber widget: from n/a through <= 4.0. | |
| Aplazada | Media (4.3) | 0.35% | — | Grafana-zabbixAI | 19/9/2025 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring. Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which… | |
| Aplazada | Alta (7.5) | 0.35% | — | ABB FlxeonAI | 18/9/2025 | 17/6/2026 | Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. | |
| Aplazada | Alta (7.5) | 0.54% | — | ABB FlxeonAI | 18/9/2025 | 17/6/2026 | Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5. | |
| Aplazada | Alta (7.3) | 0.17% | — | ABB FlxeonAI | 17/9/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions | |
| Aplazada | Alta (8.7) | 0.22% | — | ABB FlxeonAI | 17/9/2025 | 25/9/2026 | Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions | |
| Analizada | Alta (7.5) | 1.3% | — | Zabbix | 12/9/2025 | 17/6/2026 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. | |
| Analizada | Baja (2.1) | 0.19% | — | Zabbix | 12/9/2025 | 17/6/2026 | Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them. | |
| Aplazada | Alta (7.3) | 0.31% | — | Zabbix Agent 2AIZabbixAI | 12/9/2025 | 17/6/2026 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution. | |
| Aplazada | Media (5.7) | 0.17% | — | Zabbix Agent 2AI | 12/9/2025 | 17/6/2026 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system. | |
| Analizada | Media (6.5) | 1.3% | — | Apache Jackrabbit | 8/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them… | |
| Aplazada | Alta (7.5) | 1.1% | 💥 Exploit | Activepdf WebgrabberAI | 30/8/2025 | 16/6/2026 | activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although the control is not… | |
| Aplazada | Media (4.3) | 0.13% | — | Softlabbd Integrate Google DriveAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Cross Site Request Forgery.This issue affects Integrate Google Drive: from n/a through <= 1.5.2. | |
| Aplazada | Alta (8.7) | 0.36% | — | ABB Ability ZenonAI | 13/8/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14. | |
| Aplazada | Media (6.9) | 0.41% | — | ABB Ac500 V2AI | 24/7/2025 | 17/6/2026 | Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. | |
| Aplazada | Alta (8.6) | 0.19% | — | ABB Switch Actuator 4 Du-83330AIABB Switch Actuator Door Light 4 Du-83330-500AI | 22/7/2025 | 17/6/2026 | : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions. | |
| Modificada | Alta (8.8) | 0.52% | — | Apache Jackrabbit | 14/7/2025 | 17/6/2026 | Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+36 | 8/7/2025 | 17/6/2026 | Memory corruption during the image encoding process. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+36 | 8/7/2025 | 17/6/2026 | Memory corruption while processing event close when client process terminates abruptly. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm5430 Firmware+16 | 8/7/2025 | 17/6/2026 | Memory corruption while processing the TESTPATTERNCONFIG escape path. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+35 | 8/7/2025 | 17/6/2026 | Memory corruption while processing multiple simultaneous escape calls. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+36 | 8/7/2025 | 17/6/2026 | Memory corruption while processing a private escape command in an event trigger. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sa8620p FirmwareQualcomm Sa8650p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa8775p Firmware+188 | 8/7/2025 | 17/6/2026 | Transient DOS while processing received beacon frame. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Sm8635p FirmwareQualcomm Sm8650q FirmwareQualcomm Sm8735 FirmwareQualcomm Sm8750 Firmware+181 | 8/7/2025 | 17/6/2026 | Transient DOS may occur while processing malformed length field in SSID IEs. |