Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.62% | — | Scriptsbundle AdforestAI | 12/2/2026 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.1) | 0.27% | — | Scriptsbundle Adforest ElementorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle AdForest Elementor adforest-elementor allows Reflected XSS.This issue affects AdForest Elementor: from n/a through <= 3.0.11. | |
| Aplazada | Alta (8.1) | 0.59% | — | Scriptsbundle AdforestAIPHPAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scriptsbundle AdForest adforest allows PHP Local File Inclusion.This issue affects AdForest: from n/a through <= 6.0.11. | |
| Aplazada | Media (5.3) | 0.25% | — | Scriptsbundle AdforestAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in scriptsbundle AdForest adforest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdForest: from n/a through <= 6.0.11. | |
| Aplazada | Alta (7.5) | 0.34% | — | Scriptsbundle AdforestAI | 30/10/2025 | 17/6/2026 | AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization credential, which can be manipulated by… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Scriptsbundle AdforestAI | 6/9/2025 | 1/10/2026 | The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators,… | |
| Aplazada | Alta (7.2) | 0.41% | — | Adform Site TrackingAI | 19/8/2025 | 17/6/2026 | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1). | |
| Aplazada | Alta (7.1) | 0.14% | — | LeadfoxAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in leadfox Leadfox for WordPress leadfox allows Cross Site Request Forgery.This issue affects Leadfox for WordPress: from n/a through <= 2.1.9. | |
| Aplazada | Alta (7.2) | 0.66% | — | Giuliopanda AdfoAI | 24/2/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1. | |
| Aplazada | Media (6.4) | 0.32% | — | AdfoAI | 19/2/2025 | 17/6/2026 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 0.75% | — | Scriptsbundle Adforest | 22/1/2025 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they… | |
| Analizada | Media (5.4) | 0.27% | — | Scriptsbundle Adforest | 8/1/2025 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions up to, and including, 5.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete posts,… | |
| Analizada | Crítica (9.8) | 0.70% | — | Scriptsbundle Adforest | 8/1/2025 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for… | |
| Analizada | Crítica (9.8) | 1.2% | — | Scriptsbundle Adforest | 21/12/2024 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 0.34% | — | Wpfoxly Adfoxly | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5. | |
| Aplazada | Media (6.1) | 0.51% | — | AdfoAI | 14/5/2024 | 17/6/2026 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (4.3) | 0.21% | — | AdfoAI | 14/5/2024 | 17/6/2026 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() function. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (8.8) | 0.26% | — | Wpfoxly Adfoxly | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5. | |
| Analizada | Media (6.1) | 0.38% | — | Wpfoxly Adfoxly | 14/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions. | |
| Modificada | Media (5) | 2.1% | — | Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance | 13/6/2012 | 16/6/2026 | The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack. | |
| Modificada | Media (6.8) | 0.76% | — | Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance | 13/6/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attackers to hijack the authentication of administrators for requests that (1) insert XSS sequences or (2) send messages to clients. | |
| Modificada | Baja (3.5) | 1.1% | — | Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance | 13/6/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GuestAccess.jsp in the Guest/Contractor access component in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields. | |
| Modificada | Alta (7.8) | 1.7% | — | Bradford Networks Campusmanager Network Control Application Server | 11/5/2007 | 16/6/2026 | Bradford CampusManager Network Control Application Server 3.1(6) allows remote attackers to obtain sensitive information (backup, log, and configuration files) via direct request for certain files in (1) /runTime/ or (2) /remediationReports/. | |
| Modificada | Media (5) | 1.7% | — | Ratbag Dirt Track RacingRatbag Dirt Track Racing AustraliaRatbag Dirt Track Racing Sprint CarsRatbag Leadfoot+1 | 23/11/2004 | 16/6/2026 | Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified,… | |
| Modificada | Alta (7.5) | 4.4% | — | Bradford Barrett Webalizer | 22/4/2002 | 16/6/2026 | Buffer overflow in Webalizer 2.01-06, when configured to use reverse DNS lookups, allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname. |