Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.36% | — | Maya Business Paymaya-checkout-for-woocommerceAI | 20/8/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business paymaya-checkout-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maya Business: from n/a through <= 1.2.0. | |
| Aplazada | Alta (8.8) | 0.62% | — | Funnelkit Funnel Builder FOR Woocommerce CheckoutAIFunnelkit Automations Email Marketing Automation AND CRM FOR Wordpress AND WoocommerceAI | 19/8/2025 | 17/6/2026 | Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may make privilege escalation… | |
| Aplazada | Media (6.1) | 0.17% | — | LatestcheckinsAI | 16/8/2025 | 17/6/2026 | The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1. This is due to missing or incorrect nonce validation on the 'LatestCheckins' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a… | |
| Aplazada | Media (5.9) | 0.16% | — | Paloaltonetworks CheckovAI | 13/8/2025 | 17/6/2026 | A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output. | |
| Aplazada | Media (4.8) | 0.18% | — | Paloaltonetworks CheckovAI | 13/8/2025 | 17/6/2026 | An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415. | |
| Analizada | Crítica (9.8) | 0.40% | — | Checkpoint Harmony Sase | 12/8/2025 | 17/6/2026 | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties. | |
| Analizada | Media (5.3) | 0.21% | — | Checkpoint LOG Server | 6/8/2025 | 17/6/2026 | Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs | |
| Analizada | Media (5.4) | 0.46% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 6/8/2025 | 17/6/2026 | The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway. | |
| Analizada | Alta (7.8) | 0.47% | — | Felipperegazio Ssrf Check | 28/7/2025 | 17/6/2026 | Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as invalid. This oversight allows attackers to craft requests… | |
| Aplazada | Media (5.4) | 0.18% | — | Mediawiki CheckuserAI | 8/7/2025 | 17/6/2026 | The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to inject JavaScript through the uselang=x-xss language override mechanism. This issue affects Mediawiki - CheckUser extension:… | |
| Aplazada | Media (5.4) | 0.18% | — | Mediawiki CheckuserAI | 8/7/2025 | 17/6/2026 | The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit this by appending ?uselang=x-xss to the URL, causing reflected XSS when the UI renders affected message keys. This… | |
| Aplazada | Media (5.4) | 0.18% | — | Mediawiki CheckuserAI | 7/7/2025 | 17/6/2026 | The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Bsecure Your Universal CheckoutAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Universal Checkout bSecure – Your Universal Checkout bsecure allows Blind SQL Injection.This issue affects bSecure – Your Universal Checkout: from n/a through <= 1.7.9. | |
| Analizada | Media (5.3) | 0.39% | — | Checkmk | 4/7/2025 | 17/6/2026 | Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands. | |
| Aplazada | Media (5.3) | 0.35% | — | Doccheck LoginAI | 4/7/2025 | 17/6/2026 | The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin redirecting a user to login on a password protected post after the page has loaded. This makes it possible for unauthenticated attackers to read posts they should not… | |
| Analizada | Alta (7.2) | 0.21% | — | Checkpoint Smartconsole | 29/6/2025 | 17/6/2026 | Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them. | |
| Aplazada | Media (4.3) | 0.22% | — | Danbriapps PRE Publish Post ChecklistAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in danbriapps Pre-Publish Post Checklist pre-publish-post-checklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pre-Publish Post Checklist: from n/a through <= 3.1. | |
| Analizada | Alta (7.8) | 2.7% | — | Checkpoint Smartconsole | 19/6/2025 | 17/6/2026 | Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin). | |
| Aplazada | Media (4.3) | 0.16% | — | Yithemes Yith Paypal Express Checkout FOR WoocommerceAI | 17/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0. | |
| Aplazada | Media (5.3) | 0.32% | — | Centangle WOO Direct Checkout LiteAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Broken Link CheckerAI | 3/6/2025 | 17/6/2026 | The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Media (4.3) | 0.14% | — | Checkmk | 22/5/2025 | 17/6/2026 | Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data. | |
| Analizada | Alta (8.7) | 0.80% | — | Checkmk | 21/5/2025 | 17/6/2026 | Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files | |
| Aplazada | Alta (7.1) | 0.13% | — | CheckbotAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ref CheckBot checkbot allows Stored XSS.This issue affects CheckBot: from n/a through <= 1.05. | |
| Aplazada | Media (5) | 0.34% | — | Bluewavelabs CheckmateAI | 15/5/2025 | 17/6/2026 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint. |