Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.42%—Zhbackup Backup Restore MigrationAI10/9/202610/9/2026
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.
Pendiente de análisisAlta (8)1.7%—Spatie Laravel-backup-restoreAISpatie Laravel-backupAI4/9/202610/9/2026
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
AplazadaMedia (6.3)0.17%—Restore-repoAI13/8/202626/8/2026
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
AplazadaMedia (4.9)0.50%—FaissAIFlowise SimplestoreAIFlowiseai FlowiseAI8/7/20269/7/2026
Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with valid API tokens can write vector store data to arbitrary filesystem locations, potentially enabling code execution or…
AplazadaAlta (8.7)0.40%—Backup AND RestoreAI16/5/202617/6/2026
WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files…
AplazadaCrítica (9.3)1.1%—Apache Axis2AISangoma FilestoreAI24/4/202617/6/2026
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default…
AplazadaMedia (4.3)0.34%—TP Restore Categories AND TaxonomiesAI22/4/202617/6/2026
The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. The delete_term() function, which handles the 'tpmcattt_delete_term' AJAX action, does not perform any capability check (e.g., current_user_can()) to verify the user has…
AplazadaMedia (6.1)0.35%—Royal Wordpress Backup Restore PluginAI10/4/202617/6/2026
The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaMedia (4.9)0.35%—Suse Rancher Backup AND Restore Operator4/3/202617/6/2026
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
AnalizadaAlta (8.6)0.34%—Wavestore Video Management Software Server16/12/202517/6/2026
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in the ilog script. This script is being run with root privileges. This issue was…
AnalizadaMedia (5.1)0.39%—Wavestore Video Management Software Server16/12/202517/6/2026
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete files, with the permissions of dvr user, on the server using path traversal in the alog script. This issue was fixed in…
AnalizadaAlta (8.6)0.49%—Wavestore Video Management Software Server16/12/202517/6/2026
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script. This issue was fixed in version 6.44.44
AnalizadaAlta (8.6)85%⚠ Explotación activaSangoma Filestore7/11/202517/6/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection ->…
AplazadaMedia (4.3)0.29%—Wpestore WpematicoAI22/9/20251/10/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Retrieve Embedded Sensitive Data.This issue affects WPeMatico RSS Feed Fetcher: from n/a through <= 2.8.10.
AplazadaMedia (4.3)0.13%—Restore Permanently Delete Post OR Page DataAI23/8/202517/6/2026
The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the rp_dpo_dpa_ajax_dp_delete_data() function. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.4)0.48%—TIM Nguyen 1-click Backup Restore DatabaseAI4/4/202517/6/2026
Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3.
AnalizadaCrítica (9.1)0.37%—Sainwp Onestore Sites27/2/202517/6/2026
The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query…
AplazadaCrítica (9.6)0.24%—Sainwp Onestore SitesAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forgery.This issue affects OneStore Sites: from n/a through <= 0.1.1.
AplazadaAlta (8.1)0.39%—LifestylestoreAI27/1/202517/6/2026
Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise.
AplazadaCrítica (9.8)23%—WP Umbrella Update Backup Restore AND MonitoringAI8/12/202417/6/2026
The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the…
AplazadaMedia (5.3)0.38%—Wpbackitup Backup AND RestoreAI1/11/202417/6/2026
Missing Authorization vulnerability in WPBackItUp Backup and Restore WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Backup and Restore WordPress: from n/a through 1.50.
AplazadaMedia (5.4)0.32%—Wpbackitup Backup AND RestoreAI1/11/202417/6/2026
Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows . This issue affects Backup and Restore WordPress: from n/a through 1.50.
AnalizadaMedia (4.3)0.18%—Wpbackitup Backup AND Restore Wordpress26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.
AnalizadaMedia (5.4)0.23%—Tipsandtricks-hq WP Estore12/8/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
AnalizadaMedia (5.4)0.40%—Tipsandtricks-hq WP Estore12/8/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin