Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Heateor Super SocializerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | |
| Aplazada | Alta (8.8) | 0.50% | — | Heateor Super SocializerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | |
| Aplazada | Media (6.1) | 0.36% | — | Heateor Super SocializerAI | 8/7/2026 | 8/7/2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (8.1) | 0.19% | — | Heateor Social LoginAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. | |
| Aplazada | Alta (7.2) | 0.24% | — | Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+12 | 17/6/2026 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump… | |
| Pendiente de análisis | Media (6.3) | 0.18% | — | Orca Heat PumpAIOrcaAI | 1/6/2026 | 22/7/2026 | Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca… | |
| Aplazada | Alta (8.7) | 0.31% | — | Heatmiser Wifi ThermostatAI | 29/5/2026 | 21/7/2026 | Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields… | |
| Analizada | Media (5.3) | 0.13% | — | Heatmiser Wifi Thermostat | 12/4/2026 | 17/6/2026 | Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to… | |
| Aplazada | Media (6.5) | 0.22% | — | Slimndap Theater FOR WordpressAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.19. | |
| Analizada | Media (5.5) | 0.74% | — | Shuoren Smart Heating Integrated Management Platform | 23/2/2026 | 17/6/2026 | A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack… | |
| Aplazada | Media (5.5) | 0.43% | — | Sciyon Koyuan Thermoelectricity Heat Network Management SystemAI | 17/2/2026 | 17/6/2026 | A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the file /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. The manipulation of the argument PGUID leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (5.1) | 0.23% | — | Heatmiser NetmonitorAI | 12/2/2026 | 17/6/2026 | Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Heatmiser NetmonitorAI | 12/2/2026 | 17/6/2026 | Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields. | |
| Aplazada | Media (4.3) | 0.18% | — | Theatre FOR WordpressAI | 6/1/2026 | 5/10/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.19. | |
| Aplazada | Media (5.4) | 0.13% | — | Heateor Social LoginAI | 30/12/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This issue affects Heateor Social Login: from n/a through <= 1.1.39. | |
| Aplazada | Alta (8.5) | 0.18% | — | Epic Games Easy Anti CheatAI | 23/12/2025 | 17/6/2026 | Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to execute arbitrary code with elevated system privileges. Attackers can exploit the service configuration by inserting malicious code in the system root path that would execute with LocalSystem… | |
| Aplazada | Media (5.3) | 0.20% | — | Slimndap Theater FOR WordpressAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Media (6.5) | 0.31% | — | Slimndap Theater FOR WordpressAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Media (6.4) | 0.24% | — | Heateor Login Social LoginAI | 10/9/2025 | 17/6/2026 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.22% | — | Kevin Heath Tripadvisor ShortcodeAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevin heath Tripadvisor Shortcode tripadvisor-shortcode allows Stored XSS.This issue affects Tripadvisor Shortcode: from n/a through <= 2.2. | |
| Aplazada | Media (5.9) | 0.22% | — | Inspectlet Heatmaps AND User Session RecordingAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inspectlet Inspectlet – User Session Recording and Heatmaps inspectlet-heatmaps-and-user-session-recording allows Stored XSS.This issue affects Inspectlet – User Session Recording and Heatmaps: from n/a through <= 2.0. | |
| Analizada | Baja (2) | 0.36% | — | Campcodes Online Movie Theater Seat Reservation System | 19/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Movie Theater Seat Reservation System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=reserve of the component Reserve Your Seat Page. The manipulation of the argument Firstname/Lastname leads to cross site scripting. It… | |
| Analizada | Media (5.5) | 0.60% | — | Campcodes Online Movie Theater Seat Reservation System | 19/7/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage_seat.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Movie Theater Seat Reservation System | 13/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function save_movie of the file /admin/admin_class.php. The manipulation of the argument cover leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.5) | 0.45% | — | Campcodes Online Movie Theater Seat Reservation System | 11/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects an unknown part of the file /admin/manage_movie.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |