Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.21%—Wp-royal-themes AsheAI8/4/202624/7/2026
Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe: from n/a through <= 2.266.
Pendiente de análisisAlta (7.7)0.52%—Ruckus UnleashedAI26/3/202617/6/2026
Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management…
AplazadaAlta (7.5)0.58%—LT UnleashedAI12/12/202530/9/2026
The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'template' parameter in the `book` shortcode due to insufficient path sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and…
AnalizadaAlta (8.8)0.56%—Hashenudara Edoc-doctor-appointment-system11/12/202517/6/2026
edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.
AnalizadaCrítica (9.8)0.41%—Hashenudara Edoc-doctor-appointment-system2/12/202517/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.
AnalizadaMedia (6.1)0.22%—Ruckuswireless Ruckus Unleashed25/11/202517/6/2026
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
AnalizadaAlta (7.2)1.1%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format…
AnalizadaCrítica (9.1)1.1%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute…
AnalizadaCrítica (9.8)1.3%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted…
AnalizadaCrítica (9.8)1.00%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated…
AnalizadaMedia (6.3)0.37%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same…
AnalizadaMedia (5.3)0.53%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable…
AnalizadaCrítica (9.1)0.83%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary…
AnalizadaAlta (8.8)0.51%—Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector21/7/202517/6/2026
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the…
AnalizadaBaja (2.1)0.47%—Huashengdun Webssh20/7/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Huashengdun WebSSH up to 1.6.2. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument hostname/port leads to cross site scripting. The attack may be launched remotely. The exploit has…
AplazadaAlta (7.1)0.37%—Ashek AL Mahmud ALL IN ONE BOX LoginAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashek Al Mahmud all-in-one-box-login all-in-one-login allows Reflected XSS.This issue affects all-in-one-box-login: from n/a through <= 2.0.1.
AplazadaAlta (7.1)0.33%—Dashed-slug Bitcoin AND Altcoin WalletsAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashed-slug.net Bitcoin and Altcoin Wallets wallets allows Reflected XSS.This issue affects Bitcoin and Altcoin Wallets: from n/a through <= 6.3.1.
AplazadaMedia (5.4)0.29%—Wproyal Ashe ExtraAI2/1/202517/6/2026
Missing Authorization vulnerability in WP Royal Ashe Extra ashe-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through <= 1.2.92.
AplazadaMedia (4.3)0.19%—Wp-royal-themes AsheAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wproyal Ashe ashe allows Cross Site Request Forgery.This issue affects Ashe: from n/a through <= 2.233.
AplazadaMedia (5.4)0.35%—Wproyal Ashe ExtraAI2/1/202517/6/2026
Missing Authorization vulnerability in WP Royal Ashe Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through 1.2.9.
AnalizadaMedia (6.1)0.39%—Wp-royal-themes Ashe19/11/202417/6/2026
The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…
ModificadaAlta (8.8)0.42%—Gerryntabuhashe Gerryworks Post BY Mail20/10/202417/6/2026
Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privilege Escalation.This issue affects GERRYWORKS Post by Mail: from n/a through <= 1.0.
AplazadaMedia (5.9)0.44%—Rashed Latif TT Custom Post Type CreatorAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Custom Post Type Creator allows Stored XSS.This issue affects TT Custom Post Type Creator: from n/a through 1.0.
ModificadaCrítica (9.8)1.6%—Dasherr Project Dasherr20/1/202317/6/2026
erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploaded to anywhere. If an attacker uploads a php file they can execute code on the…
AnalizadaMedia (5.4)0.61%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field.