Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 306 respecto a la semana anterior
Críticas / altas1347▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.29% | — | Breeze CacheAI | 18/9/2026 | 18/9/2026 | The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored under, and served from, the clean URL's… | |
| Aplazada | Media (5.3) | 0.32% | — | Breeze CacheAI | 28/8/2026 | 28/8/2026 | The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the files it caches, allowing unauthenticated attackers to create files at arbitrary locations on the server, outside the intended cache directory. | |
| Aplazada | Alta (8.2) | 0.37% | — | BreezeAI | 18/8/2026 | 20/8/2026 | Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Breeze CacheAI | 13/7/2026 | 13/7/2026 | The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by… | |
| Aplazada | Media (5.3) | 0.27% | — | BreezeAI | 29/5/2026 | 21/7/2026 | The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wordpress_logged_in_` cookie in the `inc/cache/execute-cache.php` file when the "Cache Logged-in Users" setting is… | |
| Aplazada | Crítica (9.8) | 3.8% | — | Breeze CacheAI | 23/4/2026 | 17/6/2026 | The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Media (5.3) | 0.37% | — | BreezeAI | 19/2/2026 | 17/6/2026 | The Breeze - WordPress Cache Plugin plugin for WordPress is vulnerable to unauthorized cache clearing in all versions up to, and including, 2.2.21. This is due to the REST API endpoint `/wp-json/breeze/v1/clear-all-cache` being registered with `permission_callback => '__return_true'` and authentication being disabled… | |
| Analizada | Alta (8.5) | 0.22% | — | Flexense Syncbreeze | 3/2/2026 | 17/6/2026 | Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process. | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Media (5.1) | 0.20% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in… | |
| Analizada | Alta (8.2) | 0.40% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious requests to alter the… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.5) | 0.15% | — | Flexense DiskpulseFlexense Syncbreeze | 28/1/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token… | |
| Analizada | Alta (8.7) | 0.73% | — | Flexense Syncbreeze | 27/1/2026 | 17/6/2026 | SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability. | |
| Analizada | Alta (8.5) | 0.23% | — | Flexense Sync Breeze | 16/1/2026 | 17/6/2026 | Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries located in 'Program Files' directories to inject malicious executables and escalate… | |
| Aplazada | Media (5.3) | 0.27% | — | Cloudways BreezeAI | 6/1/2026 | 5/10/2026 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.21. | |
| Aplazada | Alta (8.7) | 0.49% | — | Flexense SyncbreezeAI | 15/12/2025 | 17/6/2026 | SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability. | |
| Aplazada | Media (6.5) | 0.31% | — | Breeze Team Breeze CheckoutAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Breeze Team Breeze Checkout breeze-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze Checkout: from n/a through <= 1.4.0. | |
| Aplazada | Media (4.3) | 0.27% | — | Cloudways BreezeAI | 18/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.2.13. | |
| Aplazada | Media (6.4) | 0.31% | — | Breeze DisplayAI | 24/4/2025 | 17/6/2026 | The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… |