Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.29% | — | Teconceptheme Electio CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows Blind SQL Injection.This issue affects Electio Core: from n/a through <= 1.4. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Teconceptheme Coven CoreAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through <= 1.3. | |
| Aplazada | Alta (7.2) | 0.20% | — | Teconceptheme AllmartAI | 4/7/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery.This issue affects Allmart: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Blaze Concepts Better Customer List FOR WoocommerceAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Better Customer List for WooCommerce woo-better-customer-list allows Reflected XSS.This issue affects Better Customer List for WooCommerce: from n/a through <= 1.2.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Kugou Technology CO LTD Kugou Concept IOSAI | 27/1/2025 | 17/6/2026 | An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via supplying a crafted link. | |
| Modificada | Crítica (9.8) | 0.48% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.33% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.29% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Aplazada | Alta (7.5) | 0.42% | — | CPF Concepts LLC BizprintAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39. | |
| Aplazada | Alta (7.1) | 0.19% | — | CPF Concepts LLC BizprintAI | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects BizPrint: from n/a through 4.5.5. | |
| Modificada | Crítica (9.8) | 0.52% | — | Dmconcept Configurator | 19/10/2023 | 17/6/2026 | DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken. | |
| Modificada | Alta (7.2) | 0.96% | — | Conceptbeans Mapwiz | 13/2/2023 | 17/6/2026 | The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Alta (8.8) | 0.68% | — | Summitmediaconcepts Ucontext FOR Clickbank | 6/9/2022 | 17/6/2026 | The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.76% | — | Summitmediaconcepts Ucontext FOR Amazon | 6/9/2022 | 17/6/2026 | The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for… | |
| Modificada | Media (6.1) | 0.81% | — | Kandnconcepts Club CMS Project Kandnconcepts Club CMS | 27/8/2020 | 17/6/2026 | KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Kandnconcepts Club CMS Project Kandnconcepts Club CMS | 27/8/2020 | 17/6/2026 | KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. | |
| Modificada | Alta (8.8) | 0.56% | — | Conceptronic Cipcamptiwl FirmwareConceptronic Cipcamptiwl WEB Firmware | 30/1/2018 | 17/6/2026 | An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account. | |
| Modificada | Alta (7.5) | 32% | — | Conceptronic Cipcamptiwl FirmwareConceptronic Cipcamptiwl WEB Firmware | 30/1/2018 | 17/6/2026 | An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device. | |
| Modificada | Alta (9.3) | 22% | — | Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+9 | 1/4/2014 | 16/6/2026 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | |
| Modificada | Media (6.8) | 11% | — | Conceptronic Cipcamptiwl 1.0 FirmwareConceptronic Cipcamptiwl | 17/1/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. | |
| Modificada | Alta (7.8) | 1.5% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as demonstrated by stored XSS attacks. | |
| Modificada | Media (4.3) | 1.2% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup. | |
| Modificada | Media (4.3) | 0.98% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action. | |
| Modificada | Media (5.8) | 1.2% | — | Conceptronic C54apm FirmwareConceptronic C54apm | 10/1/2014 | 17/6/2026 | Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to… | |
| Modificada | Media (5) | 1.4% | — | Conceptcms | 23/9/2011 | 16/6/2026 | conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files. |