Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.1) | 0.27% | — | Zyxware Disable Login Page | 2/9/2026 | 8/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. | |
| Analizada | Media (4.3) | 0.27% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.2) | 1.6% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Crítica (9.1) | 2.0% | — | Dell Cloud Disaster Recovery | 26/8/2026 | 3/9/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Pendiente de análisis | Media (5.7) | 0.22% | — | Drupal Disable Login PageAI | 25/8/2026 | 2/9/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. | |
| Analizada | Media (5.4) | 0.28% | — | Budda Login Disable | 10/7/2026 | 6/8/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4. | |
| Aplazada | Alta (7.1) | 0.44% | — | Themeisle Disable Comments FOR ANY Post TypesAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0. | |
| Analizada | Media (4.3) | 0.20% | — | Budda Login Disable | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Admin Notices Hide Dashboard NotificationsAI | 25/2/2026 | 17/6/2026 | The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs… | |
| Analizada | Media (4.2) | 0.24% | — | Zyxware Disable Login Page | 28/1/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3. | |
| Aplazada | Media (5.4) | 0.12% | — | Meks Quick Plugin DisablerAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This issue affects Meks Quick Plugin Disabler: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Content Editor FOR Specific TemplateAI | 24/10/2025 | 17/6/2026 | The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible for unauthenticated attackers to add or delete template… | |
| Analizada | Media (6.7) | 0.46% | — | Dell Cloud Disaster Recovery | 25/9/2025 | 17/6/2026 | Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Aplazada | Media (6.5) | 0.16% | — | Damian BP BP Disable Activation ReloadedAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Damian BP Disable Activation Reloaded bp-disable-activation-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Disable Activation Reloaded: from n/a through <= 1.2.1. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Disable-right-click-powered-by-pixtermeAIPixter-image-digital-licenseAI | 14/8/2025 | 17/6/2026 | The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security… | |
| Aplazada | Crítica (9.9) | 0.77% | — | Wildermyth WilderforgeAIWildermyth ExamplemodAIWildermyth WilderworkspaceAIWildermythgameproviderAI+5 | 9/6/2025 | 17/6/2026 | WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell script contexts in GitHub Actions… | |
| Aplazada | Alta (7.1) | 0.19% | — | Awplife Right Click Disable OR BANAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affects Right Click Disable OR Ban: from n/a through <= 1.1.17. | |
| Aplazada | Media (5.4) | 0.15% | — | Misteraon Simple Trackback DisablerAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in misteraon Simple Trackback Disabler simple-trackback-disabler allows Cross Site Request Forgery.This issue affects Simple Trackback Disabler: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.23% | — | Disable Elementor Editor TranslationAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from n/a through <= 1.0.2. | |
| Analizada | Media (4.3) | 0.17% | — | Exeebit Disable Auto Updates | 19/2/2025 | 17/6/2026 | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged… | |
| Analizada | Media (5.4) | 0.26% | — | Login Disable Project Login Disable | 9/1/2025 | 17/6/2026 | Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Themeisle Disable Admin NoticesAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Disable Admin Notices individually disable-admin-notices allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.6) | 0.52% | — | Wpzest Disable CommentsAI | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPZest Disable Comments | WPZest.This issue affects Disable Comments | WPZest: from n/a through 1.51. | |
| Modificada | Alta (8.8) | 0.22% | — | Atakanau Click Disable ALL | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1. | |
| Modificada | Media (4.3) | 0.40% | — | Veeam Availability OrchestratorVeeam Disaster Recovery OrchestratorVeeam Recovery Orchestrator | 7/2/2024 | 17/6/2026 | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to. |