Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.37% | — | Patrickjuchli Basic-ftpAI | 30/9/2026 | 30/9/2026 | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpjam BasicAI | 13/8/2026 | 14/8/2026 | Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpjam BasicAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | |
| Aplazada | Media (4.4) | 0.34% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 16/7/2026 | 17/7/2026 | The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.27% | — | Denishua Wpjam BasicAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0. | |
| Aplazada | Alta (8.8) | 0.52% | — | Denishua Wpjam BasicAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpkube Simple Basic Contact FormAI | 23/6/2026 | 23/6/2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or… | |
| Aplazada | Media (6.1) | 0.21% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.19% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width,… | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Drager Cc-vision BasicAIDrager Cc-vision E-calAI | 2/6/2026 | 22/7/2026 | Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system. | |
| Analizada | Media (5.1) | 0.39% | — | TFA Basic Plugins Project TFA Basic Plugins | 28/5/2026 | 21/7/2026 | An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2. | |
| Aplazada | Alta (7.5) | 0.54% | — | Patrickjuchli Basic-ftpAI | 12/5/2026 | 17/6/2026 | basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client… | |
| Analizada | Alta (7.5) | 0.49% | — | Patrickjuchli Basic-ftp | 24/4/2026 | 17/6/2026 | basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client.list()`, causing… | |
| Aplazada | Media (5.3) | 0.35% | — | Basic Google Maps PlacemarksAI | 16/4/2026 | 17/6/2026 | The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify stored map latitude and… | |
| Modificada | Baja (2.7) | 0.32% | — | Razormist Basic Library System | 13/4/2026 | 17/6/2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Razormist Basic Library System | 13/4/2026 | 17/6/2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Razormist Basic Library System | 13/4/2026 | 17/6/2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php. | |
| Modificada | Alta (8.6) | 2.8% | — | Patrickjuchli Basic-ftp | 9/4/2026 | 15/7/2026 | basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles… | |
| Analizada | Alta (8.8) | 0.27% | — | Gatech Computing FOR Good's Basic Laboratory Information System | 5/4/2026 | 24/7/2026 | C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter. Attackers can send GET requests to the users_select.php endpoint with crafted SQL payloads to… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Denishua Wpjam BasicAI | 25/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2. | |
| Analizada | Crítica (9.8) | 1.0% | — | Patrickjuchli Basic-ftp | 25/2/2026 | 17/6/2026 | The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended… | |
| Analizada | Alta (8.7) | 0.95% | — | Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+6 | 24/2/2026 | 17/6/2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the… | |
| Analizada | Crítica (9.3) | 2.7% | — | Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+6 | 24/2/2026 | 17/6/2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access,… | |
| Analizada | Alta (8.7) | 1.0% | — | Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+6 | 24/2/2026 | 17/6/2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data. | |
| Analizada | Alta (7.3) | 0.16% | — | Siemens Telecontrol Server Basic | 13/1/2026 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges. |