Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | Xwiki AdmintoolsAI | 18/11/2025 | 17/6/2026 | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still… | |
| Analizada | Alta (8.1) | 1.6% | — | Luotengyuan Myscreentools | 17/11/2025 | 17/6/2026 | MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing them to cmd.exe, allowing attackers to execute arbitrary system commands with the privileges of the user running the application.… | |
| Aplazada | Media (6.5) | 0.72% | — | Toolstack Cyan BackupAI | 8/11/2025 | 17/6/2026 | The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on… | |
| Analizada | Media (6.1) | 0.24% | — | Nuxt Devtools | 7/11/2025 | 17/6/2026 | A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtools | |
| Aplazada | Media (5.8) | 0.10% | — | Voidtools EverythingAI | 4/11/2025 | 17/6/2026 | The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements)… | |
| Aplazada | Media (6.1) | 0.15% | — | Mahype Pagerank ToolsAI | 4/11/2025 | 17/6/2026 | The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the pr_save_settings() function and insufficient input sanitization. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Iib0011 Omni-toolsAI | 30/10/2025 | 17/6/2026 | iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. | |
| Analizada | Media (4.3) | 0.29% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Analizada | Media (5.4) | 0.25% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (5.4) | 0.22% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (5.5) | 0.25% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (6.1) | 0.23% | — | Oracle JD Edwards Enterpriseone Tools | 21/10/2025 | 17/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful… | |
| Analizada | Media (4.9) | 0.37% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (6.1) | 0.23% | — | Oracle JD Edwards Enterpriseone Tools | 21/10/2025 | 17/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne… | |
| Analizada | Media (6.1) | 0.25% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Alta (7.5) | 0.43% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Media (5.4) | 0.22% | — | Oracle Peoplesoft Enterprise Peopletools | 21/10/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Aplazada | Media (6.4) | 0.30% | — | Xx2wp Integration ToolsAI | 18/10/2025 | 17/6/2026 | The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display_embed' shortcode in all versions up to, and including, 1.9.9. This is due to the plugin not properly sanitizing user input and output of the 'post_id' parameter. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.45% | — | Starcitizen.tools CitizenAI | 17/10/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonAttributes function assigns innerHTML from a source element’s textContent when… | |
| Aplazada | Media (4.3) | 0.13% | — | FunkitoolsAI | 15/10/2025 | 17/6/2026 | The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the saveFields() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted… | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa💥 PoC | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Aplazada | Alta (7.6) | 0.28% | — | Vmware ToolsAIVmware VcenterAIVmware ESXAI | 29/9/2025 | 17/6/2026 | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation… | |
| Aplazada | Media (6.5) | 0.20% | — | Milan Petrovic GD GD Bbpress ToolsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD bbPress Tools gd-bbpress-tools allows DOM-Based XSS.This issue affects GD bbPress Tools: from n/a through <= 3.5.3. | |
| Aplazada | Media (5.4) | 0.14% | — | Swiftninjapro Developer Tools BlockerAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SwiftNinjaPro Developer Tools Blocker swiftninjapro-inspect-element-console-blocker allows Cross Site Request Forgery.This issue affects Developer Tools Blocker: from n/a through <= 3.2.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Codestag StagtoolsAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ram Ratan Maurya Stagtools stagtools allows Stored XSS.This issue affects Stagtools: from n/a through <= 2.3.8. |