Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.18% | — | IBM Websphere Application Server | 3/3/2026 | 17/6/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings. | |
| Analizada | Media (4.8) | 0.31% | — | Audiobookshelf Mobile APP | 26/2/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges (or… | |
| Analizada | Media (4.8) | 0.28% | — | AudiobookshelfAudiobookshelf Mobile APP | 26/2/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges… | |
| Aplazada | Alta (7.2) | 0.85% | — | Webappick CTX FeedAI | 19/2/2026 | 17/6/2026 | The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop… | |
| Aplazada | Alta (7.1) | 0.29% | — | Netapp StoragegridAI | 18/2/2026 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with… | |
| Analizada | Media (4.9) | 0.33% | — | IBM Websphere Application Server | 17/2/2026 | 17/6/2026 | IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration of security settings. | |
| Analizada | Media (5.5) | 0.44% | — | Fabian Online Application System FOR Admission | 8/2/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the component Login Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit… | |
| Modificada | Media (5.5) | 0.27% | — | Zipperapp MY Teditor | 5/2/2026 | 5/7/2026 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | |
| Analizada | Alta (7.6) | 0.48% | — | IBM Websphere Application Server | 2/2/2026 | 17/6/2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.19% | — | Atheros Coex Service ApplicationAI | 27/1/2026 | 17/6/2026 | Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup. | |
| Aplazada | Media (5.3) | 0.35% | — | Webappick CTX FeedAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WebAppick CTX Feed webappick-product-feed-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CTX Feed: from n/a through <= 6.6.18. | |
| Aplazada | Media (6.5) | 0.22% | — | Nsquared Simply Schedule AppointmentsAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15. | |
| Analizada | Baja (2.3) | 0.15% | — | Oracle SUN ZFS Storage Appliance KIT | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle… | |
| Analizada | Media (6.9) | 0.22% | — | Netapp Ontap | 12/1/2026 | 17/6/2026 | ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none. | |
| Modificada | Crítica (9.6) | 1.3% | 💥 PoC | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 6/10/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Aplazada | Alta (7.1) | 0.18% | — | Nebelhorn Blappsta Mobile APP PluginAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App:… | |
| Aplazada | Alta (7.5) | 0.25% | — | Knowband Mobile APP BuilderAI | 31/12/2025 | 17/6/2026 | The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users. | |
| Aplazada | Media (5.1) | 0.17% | — | Smarthouse WebappAI | 24/12/2025 | 17/6/2026 | SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various… | |
| Aplazada | Media (5.3) | 0.35% | — | Simply Schedule AppointmentsAI | 19/12/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, which… | |
| Analizada | Baja (2) | 0.32% | — | Anisha Online Appointment Booking System | 19/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the file /admin/deletemanager.php. The manipulation of the argument managername results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (6.1) | 1.1% | — | Zohocorp Manageengine Applications Manager | 18/12/2025 | 30/9/2026 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | |
| Analizada | Media (5.5) | 0.36% | — | Anisha Online Appointment Booking System | 17/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /admin/deletemanagerclinic.php. Performing manipulation of the argument clinic results in sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.5) | 0.31% | — | Menulux Software INC Mobile APPAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers. This issue affects Mobile App: before 9.5.8. | |
| Aplazada | Media (5.3) | 0.28% | — | Hippoo Mobile APPAI | 12/12/2025 | 7/10/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback =>… | |
| Analizada | Media (6.5) | 0.57% | — | A1apps Office App-edit Word, PDF File | 10/12/2025 | 17/6/2026 | A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal. |