Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.48%—Nextgeneditor Nextgen Editor19/6/202619/8/2026
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract…
AplazadaMedia (6.3)0.16%—HCL VerseAICompose-rich-editorAI19/6/202622/6/2026
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
Pendiente de análisisCrítica (9.2)0.29%—Rockwellautomation Factorytalk Historian Site EditionAI16/6/202630/9/2026
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
AplazadaAlta (8.5)0.11%—Mobaxterm Personal EditionAI12/6/202617/6/2026
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an attacker with local…
AplazadaAlta (8.5)0.11%—Mobaxterm Personal EditionAI12/6/202617/6/2026
MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s…
AnalizadaMedia (5.4)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.1)0.70%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
ModificadaMedia (6.5)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
ModificadaMedia (6.1)0.46%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.1)0.41%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (5.9)0.43%—Fastnetmon Community EditionAI2/6/202622/7/2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without…
AplazadaAlta (7.5)0.51%💥 PoCLaunch-editorAIVitejs ViteAI1/6/20264/9/2026
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has…
AplazadaMedia (6.5)0.44%—Fastnetmon Community EditionAI26/5/202624/7/2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end…
AnalizadaAlta (7.7)0.59%—UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
AnalizadaCrítica (10)46%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
AnalizadaCrítica (10)1.8%⚠ Explotación activaUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2822/5/202623/7/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
AplazadaCrítica (9.3)0.60%—WP Super EditAI15/5/202617/6/2026
WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and…
AnalizadaMedia (6.1)0.52%⚠ Explotación activa💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AplazadaAlta (8.4)0.18%—Bytello Share Windows EditionAI13/5/202617/6/2026
Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.
AplazadaAlta (7.6)0.38%—Realmag777 Bear Woo-bulk-editorAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1.
AplazadaMedia (6.4)0.32%—Credits ShortcodeAI12/5/202617/6/2026
The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.7)0.37%—Brave CMSAILaravel BladeAICkeditorAI8/5/202617/6/2026
Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is…