Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Simbunch Simgenealogy | 19/6/2026 | 19/8/2026 | Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy, view=latest parameters and inject malicious… | |
| Analizada | Alta (8.8) | 0.44% | — | Kreaweb Genealogy | 7/4/2026 | 24/7/2026 | Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces and unrestricted… | |
| Aplazada | Alta (8.8) | 0.24% | — | Meneame English PliggAI | 6/3/2026 | 17/6/2026 | Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to index.php with crafted SQL payloads in the search parameter to extract sensitive database… | |
| Analizada | Baja (2.1) | 0.45% | — | Cocoteanet Cyreneadmin | 19/2/2026 | 17/6/2026 | A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System Info Endpoint. Executing a manipulation can lead to improper authorization. The attack can be launched remotely. The exploit has been publicly… | |
| Analizada | Baja (2.1) | 0.61% | — | Cocoteanet Cyreneadmin | 19/2/2026 | 17/6/2026 | A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component Image Handler. Performing a manipulation of the argument Avatar results in path traversal. The attack can be initiated remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.1) | 0.11% | — | Reneade Sensitive TAG CloudAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This issue affects SensitiveTagCloud: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Akdevs Genealogical-treeAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in akdevs Genealogical Tree genealogical-tree allows Stored XSS.This issue affects Genealogical Tree: from n/a through <= 2.2.7. | |
| Analizada | Media (5.4) | 0.30% | — | Kreaweb Genealogy | 18/8/2025 | 17/6/2026 | Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another user’s session, leading to session hijacking, data theft, and UI manipulation. This… | |
| Analizada | Media (5.4) | 0.33% | — | Kreaweb Genealogy | 18/8/2025 | 17/6/2026 | Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another user’s session, leading to session hijacking, data theft, and UI manipulation. This… | |
| Modificada | Baja (3.5) | 0.19% | — | Reneade Twitterposts | 15/5/2025 | 17/6/2026 | The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Media (5.3) | 0.52% | — | WP Genealogy Developers WP GenealogyAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Black and White WP Genealogy – Your Family History Website wpgenealogy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Genealogy – Your Family History Website: from n/a through <= 0.1.9. | |
| Analizada | Media (4.2) | 0.28% | — | Reneade Postlists | 9/1/2025 | 17/6/2026 | The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Modificada | Alta (8.8) | 0.59% | — | Tngsitebuilding THE Next Generation OF Genealogy Sitebuilding | 8/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in The Next Generation of Genealogy Sitebuilding up to 11.1.0. This issue affects some unknown processing of the file /timeline2.php. The manipulation of the argument primaryID leads to sql injection. The attack may be initiated remotely. The exploit… | |
| Modificada | Alta (9) | 2.6% | — | Enea OSEEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the… | |
| Modificada | Alta (10) | 3.3% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson DL 8000 Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device… | |
| Modificada | Alta (10) | 4.9% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service. | |
| Modificada | Alta (10) | 5.0% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Lythgoes THE Next Generation OF Genealogy Sitebuilding | 14/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchform.php in The Next Generation of Genealogy Sitebuilding (TNG) 7.1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Phpgenealogy | 2/10/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Meneame | 5/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Meneame before 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |