Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | Magnigenie RestropressAI | 21/9/2026 | 21/9/2026 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-chosen total, down to and including zero. | |
| Aplazada | Media (6.5) | 0.27% | — | Magnigenie RestropressAI | 18/9/2026 | 18/9/2026 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order. | |
| Aplazada | Alta (8.8) | 0.50% | — | GeniewordsAI | 13/9/2026 | 14/9/2026 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page. | |
| Aplazada | Media (6.7) | 0.11% | — | GeniezoneAI | 7/9/2026 | 8/9/2026 | In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781. | |
| Aplazada | Media (4.4) | 0.12% | — | GeniezoneAI | 7/9/2026 | 28/9/2026 | In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674. | |
| Aplazada | Alta (8.8) | 0.26% | — | Genieacs-mcpAI | 25/8/2026 | 9/9/2026 | genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKEN is unset and the httpSrv.Start(addr) branch does not validate the Host or Origin… | |
| Aplazada | Alta (7.1) | 0.25% | — | GetgenieAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | GetgenieAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | GetgenieAI | 16/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions. | |
| Aplazada | Alta (8.1) | 1.4% | — | Netgear GenieAI | 11/5/2026 | 17/6/2026 | Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js when a user reads from an external FORGE_BASE_URL. | |
| Analizada | Alta (7.5) | 0.44% | — | Genieacs | 7/4/2026 | 20/7/2026 | In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. | |
| Aplazada | Baja (2.1) | 0.36% | — | Codegenieapp Serverless-expressAI | 16/3/2026 | 17/6/2026 | A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass.… | |
| Aplazada | Media (5.4) | 0.38% | — | GetgenieAI | 13/3/2026 | 17/6/2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2. This is due to missing validation on the `id` parameter in the `create()` method of the `GetGenieChat` REST API endpoint. The method accepts a user-controlled post ID and, when a post with… | |
| Aplazada | Media (6.4) | 0.23% | — | GetgenieAI | 13/3/2026 | 17/6/2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2 due to missing validation on a user controlled key in the `action` function. This makes it possible for authenticated attackers, with Author-level access and above, to update post metadata… | |
| Aplazada | Baja (2.1) | 0.39% | — | Codegenieapp Serverless-expressAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This manipulation of the argument filter causes injection. The attack may be initiated remotely. The exploit has been made available to the public… | |
| Aplazada | Media (4.9) | 0.27% | — | Roxnor GetgenieAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Roxnor GetGenie getgenie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetGenie: from n/a through <= 4.3.0. | |
| Aplazada | Media (4.3) | 0.24% | — | GetgenieAI | 16/1/2026 | 17/6/2026 | The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete… | |
| Aplazada | Media (5.3) | 0.22% | — | Magnigenie RestropressAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.7. | |
| Aplazada | Media (6.5) | 0.16% | — | Magnigenie RestropressAI | 30/12/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Stored XSS.This issue affects RestroPress: from n/a through <= 3.2.8.6. | |
| Aplazada | Media (6.5) | 0.24% | — | Magnigenie RestropressAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.3.5. | |
| Aplazada | Crítica (9.8) | 2.3% | — | Magnigenie RestropressAI | 3/10/2025 | 17/6/2026 | The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT… | |
| Aplazada | Media (5.5) | 0.30% | — | Esigngenie Foxit Esign FOR WordpressAI | 6/6/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for WordPress esign-genie-for-wp allows Retrieve Embedded Sensitive Data.This issue affects Foxit eSign for WordPress: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.1) | 0.42% | — | Magnigenie RestropressAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Reflected XSS.This issue affects RestroPress: from n/a through <= 3.2.8.4. | |
| Aplazada | Alta (8.5) | 0.34% | — | Magnigenie Review-stars-count-for-woocommerceAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce review-stars-count-for-woocommerce allows SQL Injection.This issue affects Review Stars Count For WooCommerce: from n/a through <= 2.0. | |
| Aplazada | Media (4.3) | 0.25% | — | Magnigenie RestropressAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.8. |