Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.48% | — | Nextgeneditor Nextgen Editor | 19/6/2026 | 19/8/2026 | Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract… | |
| Aplazada | Media (6.3) | 0.16% | — | HCL VerseAICompose-rich-editorAI | 19/6/2026 | 22/6/2026 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations. | |
| Pendiente de análisis | Crítica (9.2) | 0.29% | — | Rockwellautomation Factorytalk Historian Site EditionAI | 16/6/2026 | 30/9/2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. | |
| Aplazada | Alta (8.5) | 0.11% | — | Mobaxterm Personal EditionAI | 12/6/2026 | 17/6/2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an attacker with local… | |
| Aplazada | Alta (8.5) | 0.11% | — | Mobaxterm Personal EditionAI | 12/6/2026 | 17/6/2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s… | |
| Analizada | Media (5.4) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.1) | 0.70% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | 💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Media (6.5) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | |
| Modificada | Media (6.1) | 0.46% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.9) | 0.43% | — | Fastnetmon Community EditionAI | 2/6/2026 | 22/7/2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without… | |
| Aplazada | Alta (7.5) | 0.51% | 💥 PoC | Launch-editorAIVitejs ViteAI | 1/6/2026 | 4/9/2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has… | |
| Aplazada | Media (6.5) | 0.44% | — | Fastnetmon Community EditionAI | 26/5/2026 | 24/7/2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end… | |
| Analizada | Alta (7.7) | 0.59% | — | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information. | |
| Analizada | Crítica (10) | 46% | ⚠ Explotación activa💥 Exploit | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | |
| Analizada | Crítica (10) | 1.8% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+28 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. | |
| Analizada | Crítica (10) | 15% | ⚠ Explotación activa💥 Exploit | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | |
| Aplazada | Crítica (9.3) | 0.60% | — | WP Super EditAI | 15/5/2026 | 17/6/2026 | WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and… | |
| Analizada | Media (6.1) | 0.52% | ⚠ Explotación activa💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Alta (8.4) | 0.18% | — | Bytello Share Windows EditionAI | 13/5/2026 | 17/6/2026 | Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer. | |
| Aplazada | Alta (7.6) | 0.38% | — | Realmag777 Bear Woo-bulk-editorAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1. | |
| Aplazada | Media (6.4) | 0.32% | — | Credits ShortcodeAI | 12/5/2026 | 17/6/2026 | The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.7) | 0.37% | — | Brave CMSAILaravel BladeAICkeditorAI | 8/5/2026 | 17/6/2026 | Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is… |