Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.76% | — | Simalexan Api-lambda-send-email-sesAI | 13/9/2026 | 14/9/2026 | A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing… | |
| Aplazada | Crítica (9.1) | 0.66% | 💥 PoC | Alexantr FilemanagerAI | 29/6/2026 | 30/6/2026 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component | |
| Aplazada | Media (5.9) | 0.22% | — | Alexandre Froger WP WeixinAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger WP Weixin wp-weixin allows Stored XSS.This issue affects WP Weixin: from n/a through <= 1.3.16. | |
| Aplazada | Alta (7.1) | 0.15% | — | Alexander Rauscha MlanguageAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage mlanguage allows Stored XSS.This issue affects mLanguage: from n/a through <= 1.6.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Alexander Weleczka Fontawesome.io ShortcodesAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io ShortCodes: from n/a through 1.0. | |
| Aplazada | Media (4.3) | 0.43% | — | Alexander Volkov ChatterAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1. | |
| Aplazada | Media (4.3) | 0.38% | — | Alexacrm Dynamics 365 IntegrationAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13. | |
| Aplazada | Media (5.4) | 0.36% | — | Alexacrm Dynamics 365 IntegrationAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12. | |
| Aplazada | Media (6.5) | 0.26% | — | Alexandremagno WP AgendaAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alexandremagno WP Agenda wp-agenda allows Stored XSS.This issue affects WP Agenda: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.41% | — | Jerin K Alexander Events Manager PRO ExtendedAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended events-manager-pro-extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through <= 0.1. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Alexander DE Ridder INK OfficialAI | 23/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Upload a Web Shell to a Web Server.This issue affects INK Official: from n/a through <= 4.1.2. | |
| Aplazada | Media (5.3) | 0.58% | — | Alexacrm Dynamics 365 IntegrationAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17. | |
| Aplazada | Media (4.3) | 0.21% | — | Perrinalexandre05 AffieasyAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in perrinalexandre05 AffiEasy affieasy.This issue affects AffiEasy: from n/a through <= 1.1.4. | |
| Modificada | Alta (8.8) | 0.23% | — | Mariosalexandrou Republish OLD Posts | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21. | |
| Modificada | Media (6.1) | 0.39% | — | Alexanderlivanov Fotoscms2 | 28/10/2023 | 17/6/2026 | A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affects unknown code of the file profile.php of the component Cookie Handler. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Modificada | Media (5.3) | 0.59% | — | Alexanderschneider User Access Manager | 30/8/2023 | 17/6/2026 | The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations. | |
| Modificada | Alta (7.6) | 0.67% | — | Amazon Alexa | 24/5/2023 | 17/6/2026 | Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by… | |
| Modificada | Alta (8.8) | 0.40% | — | Lenovo Smart Clock Essential With Alexa Built IN Firmware | 1/5/2023 | 17/6/2026 | A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Alexandriabooklibrary Alexandria Book Library | 22/2/2018 | 17/6/2026 | SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Paulalexanderformayor Paul Alexander Campaign | 16/10/2014 | 17/6/2026 | The Paul Alexander Campaign (aka hr.apps.n51261427) application 4.5.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.1% | — | Alexander Palmo Simple PHP Blog | 29/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry parameter to delete.php or (2) category parameter to index.php. | |
| Modificada | Alta (7.5) | 3.6% | — | Alexander V. Lukyanov Lftp | 6/7/2010 | 16/6/2026 | The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Alexandre Dubus Audistat | 23/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.89% | 💥 Exploit | Alexandre Dubus Audistat | 23/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Alexandre Dubus Audistat | 23/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter. |