Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Jevon-zhong Ai-doctorAI | 9/8/2026 | 12/8/2026 | A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack must be initiated from a local position.… | |
| Aplazada | Media (4.8) | 0.23% | — | Ideagen DevonwayAI | 8/1/2026 | 17/6/2026 | Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS. | |
| Aplazada | Alta (7.5) | 0.46% | — | Kevonadonis WP AbstractsAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows PHP Local File Inclusion.This issue affects WP Abstracts: from n/a through <= 2.7.4. | |
| Aplazada | Alta (8.1) | 0.72% | — | Snstheme EvonAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Evon snsevon allows PHP Local File Inclusion.This issue affects Evon: from n/a through <= 3.4. | |
| Aplazada | Alta (7.1) | 0.19% | — | Kevonadonis WP AbstractsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Cross Site Request Forgery.This issue affects WP Abstracts: from n/a through <= 2.7.5. | |
| Analizada | Media (5.4) | 0.22% | — | Kevonadonis WP Abstracts | 12/2/2025 | 17/6/2026 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing nonce validation on multiple functions. This makes it possible for unauthenticated attackers to delete arbitrary accounts via a forged request granted they can trick a… | |
| Analizada | Media (6.1) | 0.20% | — | Kevonadonis WP Abstracts | 18/1/2025 | 17/6/2026 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing nonce validation on the wpabstracts_load_status() and wpabstracts_delete_abstracts() functions. This makes it possible for unauthenticated attackers to inject malicious… | |
| Modificada | Media (4.8) | 0.26% | — | Kevonadonis WP Abstracts | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.7.1. | |
| Modificada | Media (4.8) | 0.31% | — | Kevonadonis WP Abstracts | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.6.5. | |
| Modificada | Media (4.8) | 0.47% | — | Kevonadonis WP Abstracts | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.3 versions. | |
| Analizada | Alta (8.8) | 0.26% | — | Kevonadonis WP Abstracts | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |
| Analizada | Media (6.1) | 0.38% | — | Kevonadonis WP Abstracts | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |
| Modificada | Alta (8.8) | 0.83% | — | IBM Sevone Network Performance Management | 7/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely. | |
| Modificada | Alta (8.8) | 0.82% | — | IBM Sevone Network Performance Management | 7/6/2022 | 17/6/2026 | A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely. | |
| Modificada | Alta (8.8) | 4.1% | — | IBM Sevone Network Performance Management | 7/6/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the attack remotely. | |
| Modificada | Media (4.8) | 0.62% | — | Evona PER Page ADD TO Head | 13/9/2021 | 17/6/2026 | The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues. | |
| Modificada | Media (4.3) | 0.48% | — | Evona PER Page ADD TO Head | 13/9/2021 | 17/6/2026 | The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to… | |
| Modificada | Media (6.1) | 0.90% | — | Devondev Simple Matted Thumbnails | 10/9/2021 | 17/6/2026 | The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.01. | |
| Modificada | Media (5) | 1.4% | — | Devonit Thin-client Management Tool | 25/8/2010 | 16/6/2026 | The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover the secret value, and consequently obtain administrative control over client machines, by sniffing the network. | |
| Modificada | Alta (7.5) | 2.4% | — | Devonit Thin-client Management Tool | 25/8/2010 | 16/6/2026 | Buffer overflow in tm-console-bin in the DevonIT thin-client management tool might allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.99% | — | Jevontech Phpenpals | 29/5/2009 | 16/6/2026 | SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074. | |
| Modificada | Media (5) | 1.4% | — | Jeroen Vennegoor Jevoncms | 27/9/2006 | 16/6/2026 | Jeroen Vennegoor JevonCMS, possibly pre alpha, allows remote attackers to obtain sensitive information via a direct request for php/main/phplib files (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysql.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, and (7) db_pgsql.inc; and (8) db_sybase.inc, which reveals the… | |
| Modificada | Alta (7.5) | 2.5% | — | Jevontech Phpenpals | 4/1/2006 | 16/6/2026 | SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected. |