Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.56% | — | Thinking Software Technology EfenceAI | 14/9/2026 | 18/9/2026 | EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Aplazada | Alta (8.7) | 0.79% | — | Thinking Software Technology EfenceAI | 26/8/2026 | 26/8/2026 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Alta (8.8) | 0.48% | — | Thinking Software Technology EfenceAI | 26/8/2026 | 26/8/2026 | Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents. | |
| Aplazada | Crítica (9.3) | 0.90% | — | Thinking Software Technology EfenceAI | 26/8/2026 | 3/9/2026 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Alta (8.8) | 0.79% | — | PacketfenceAI | 6/8/2026 | 31/8/2026 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | |
| Aplazada | Alta (8.7) | 0.65% | — | Wordfence Anti Malware Security AND Bruteforce FirewallAI | 16/5/2026 | 17/6/2026 | WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with path traversal… | |
| Analizada | Media (6.5) | 0.27% | — | Mega-fence Project Mega-fence | 5/1/2026 | 17/6/2026 | Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without validating a trusted proxy chain. An attacker can supply an arbitrary XFF value in a remote request to spoof the client IP, which is then propagated to security-relevant state (e.g.,… | |
| Aplazada | Alta (7.1) | 0.33% | — | Harshtohit111 Fence URLAI | 28/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harshtohit111 Fence URL fence-url allows Stored XSS.This issue affects Fence URL: from n/a through <= 2.0.0. | |
| Aplazada | Alta (8.8) | 1.4% | — | Redhat Fence Agents Remediation OperatorAI | 12/8/2024 | 17/6/2026 | A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted… | |
| Modificada | Media (5.4) | 0.31% | — | Mainwp Wordfence Extension | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in MainWP MainWP Wordfence Extension.This issue affects MainWP Wordfence Extension: from n/a through 4.0.7. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 1.0% | — | Thinkingsoftware Efence | 16/6/2023 | 17/6/2026 | Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database. | |
| Modificada | Crítica (9.8) | 1.0% | — | Thinkingsoftware Efence | 31/1/2023 | 17/6/2026 | Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database. | |
| Modificada | Media (4.8) | 0.81% | — | Wordfence Security | 23/9/2022 | 17/6/2026 | The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to… | |
| Modificada | Media (5.9) | 0.83% | — | Clusterlabs Fence-agents | 2/1/2020 | 17/6/2026 | In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates. | |
| Modificada | Media (5) | 2.2% | — | Clusterlabs Fence-agentsRedhat Enterprise LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 30/7/2019 | 17/6/2026 | A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM… | |
| Modificada | Media (6.1) | 1.0% | — | Wordfence | 25/4/2019 | 17/6/2026 | The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as the firewall rules are not maintained as part of the Wordfence software but rather it is a set of rules hosted on vendor… | |
| Modificada | Media (6.1) | 1.2% | — | Wordfence Security | 28/8/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php. | |
| Modificada | Alta (7.8) | 0.84% | — | F-secure Xfence | 13/6/2018 | 17/6/2026 | An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned… | |
| Modificada | Crítica (9.8) | 1.6% | — | Packetfence | 1/2/2018 | 16/6/2026 | html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username. | |
| Modificada | Crítica (9.8) | 1.5% | — | Packetfence | 1/2/2018 | 16/6/2026 | The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password. | |
| Modificada | Alta (7.8) | 1.1% | — | Fujitsu Fence-explorer | 15/9/2017 | 17/6/2026 | Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (4.3) | 2.3% | — | Wordfence Security Project Wordfence Security | 6/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin/admin.php. | |
| Modificada | Media (5.4) | 0.27% | — | Defence.pk | 23/9/2014 | 17/6/2026 | The Defence.pk (aka com.tapatalk.defencepkforums) application 2.4.13.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Efence Project Efence | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in callback.php in the efence plugin 1.3.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) zoneid, (3) pubKey, or (4) privKey parameter. |