Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
1102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | 0.27% | — | Wp-buy Visitor Traffic Real Time StatisticsAI | 3/10/2026 | 3/10/2026 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7) | 0.28% | — | Apache Traffic ServerAI | 2/10/2026 | 2/10/2026 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x… | |
| Aplazada | Alta (7.2) | 0.19% | — | Visitors Traffic Real Time Statistics PROAI | 2/10/2026 | 2/10/2026 | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers… | |
| Aplazada | Media (5.3) | 0.18% | — | Villatheme AffiAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | |
| Aplazada | Alta (7.7) | 0.15% | — | Canva AffinityAI | 17/9/2026 | 18/9/2026 | The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 11/9/2026 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of… | |
| Aplazada | Media (5.5) | 0.76% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 8/9/2026 | A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.69% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now… | |
| Analizada | Alta (8.4) | 0.22% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 3/9/2026 | 9/9/2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Alta (7.2) | 0.24% | — | Ifeelweb Affiliate Super AssistentAI | 1/9/2026 | 1/9/2026 | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Visitor Traffic Real Time Statistics PROAI | 27/8/2026 | 28/8/2026 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Redefiningtheweb Affiliate PROAI | 24/8/2026 | 24/8/2026 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpaffiliatemanager Affiliates ManagerAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpaffiliatemanager Affiliates ManagerAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | |
| Aplazada | Media (4.9) | 0.44% | — | Servit Affiliate-toolkitAI | 14/8/2026 | 14/8/2026 | The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Alta (8.5) | 0.36% | — | Visitor Traffic Real Time Statistics PROAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitors Traffic Real Time StatisticsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | AffiliatewpAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | |
| Analizada | Crítica (9.8) | 0.48% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/8/2026 | 10/8/2026 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This… | |
| Analizada | Media (4.4) | 0.16% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 12/8/2026 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such… | |
| Analizada | Media (4.9) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 13/8/2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client… | |
| Analizada | Alta (7.5) | 0.41% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 9/8/2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the… |