Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 1.8% | — | Zyxel Ex3510-b1 FirmwareZyxel Ex3600-t0 FirmwareZyxel Ex5401-b1 FirmwareZyxel Ex5510-b0 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 1.2% | — | Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 0.81% | — | Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service… | |
| Aplazada | Alta (8.3) | 7.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 23/2/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. | |
| Aplazada | Alta (8.8) | 0.36% | — | Microasp Portal Plus CMSAI | 22/2/2026 | 17/6/2026 | microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to… | |
| Aplazada | Media (5.3) | 0.15% | — | Posimyth THE Plus Addons FOR ElementorAI | 22/2/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in… | |
| Aplazada | Baja (2.1) | 0.35% | — | Dromara Ruoyi-vue-plusAI | 20/2/2026 | 17/6/2026 | A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be initiated remotely. The exploit is… | |
| Aplazada | Media (4.3) | 0.13% | — | Whatsiplus Scheduled Notification FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing nonce validation on the 'wsnfw_save_users_settings' AJAX action. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Media (6.4) | 0.32% | — | Essentialplugin Album AND Image Gallery Plus LightboxAI | 19/2/2026 | 17/6/2026 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `aigpl-gallery-album` shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (7.3) | 0.21% | — | Notepad-plus-plus Notepad++ | 19/2/2026 | 17/6/2026 | Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory.… | |
| Aplazada | Media (4.3) | 0.18% | — | THE Plus AddonsAI | 18/2/2026 | 17/6/2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing users only with… | |
| Analizada | Alta (8.8) | 0.45% | — | Ciprianmp Phpmychat-plus | 5/2/2026 | 17/6/2026 | phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database information by… | |
| Analizada | Alta (8.2) | 0.39% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+1 | 4/2/2026 | 17/6/2026 | A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response… | |
| Analizada | Alta (7.7) | 1.8% | ⚠ Explotación activa💥 PoC | Notepad-plus-plus Notepad++ | 3/2/2026 | 17/6/2026 | Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an… | |
| Aplazada | Media (6.4) | 0.30% | — | Buynowplus BUY NOW PlusAI | 28/1/2026 | 17/6/2026 | The Buy Now Plus – Buy Now buttons for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buynowplus' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on shortcode attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.5) | 0.15% | — | Sandboxie PlusAI | 21/1/2026 | 17/6/2026 | Sandboxie Plus 0.7.2 contains an unquoted service path vulnerability in the SbieSvc service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions during service startup. | |
| Analizada | Crítica (9.8) | 3.8% | 💥 PoC | Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+159 | 20/1/2026 | 17/6/2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. | |
| Aplazada | Alta (7.5) | 0.43% | — | Kraftplugins Demo Importer PlusAI | 17/1/2026 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable… | |
| Analizada | Alta (7.3) | 0.13% | — | Lenovo Thinkplus Fu100 FirmwareLenovo Thinkplus Fu200 FirmwareLenovo Thinkplus Tu800 FirmwareLenovo Thinkplus Tsd303 Firmware | 14/1/2026 | 17/6/2026 | A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication and enroll an untrusted fingerprint. | |
| Analizada | Media (6.8) | 0.10% | — | Lenovo Thinkplus Fu100 FirmwareLenovo Thinkplus Fu200 FirmwareLenovo Thinkplus Tu800 FirmwareLenovo Thinkplus Tsd303 Firmware | 14/1/2026 | 17/6/2026 | A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to gain access to sensitive device information. | |
| Analizada | Media (5.1) | 0.14% | — | Lenovo Thinkplus Fu100 FirmwareLenovo Thinkplus Fu200 FirmwareLenovo Thinkplus Tu800 FirmwareLenovo Thinkplus Tsd303 Firmware | 14/1/2026 | 17/6/2026 | A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on the drive. | |
| Analizada | Alta (7) | 0.58% | — | Explorerplusplus Explorer++ | 13/1/2026 | 17/6/2026 | Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious… | |
| Aplazada | Alta (8.5) | 0.15% | — | Sandboxie-plusAI | 13/1/2026 | 17/6/2026 | Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup. | |
| Aplazada | Alta (8.5) | 0.15% | — | Coolmaster MasterplusAI | 13/1/2026 | 17/6/2026 | CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system reboot. | |
| Analizada | Media (5.5) | 0.60% | 💥 PoC | Zohocorp Manageengine Admanager Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module |