Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.4% | — | HummingbirdAI | 5/9/2026 | 8/9/2026 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to… | |
| Aplazada | Alta (7.2) | 0.37% | — | HummingbirdAI | 4/9/2026 | 8/9/2026 | The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | |
| Aplazada | Alta (7.5) | 1.9% | — | HummingbirdAI | 18/12/2025 | 1/10/2026 | The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials. | |
| Modificada | Alta (8.8) | 0.55% | — | Incsub Hummingbird | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1. | |
| Modificada | Alta (8.8) | 0.21% | — | Wpmudev Hummingbird | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1. | |
| Modificada | Media (5.3) | 0.28% | — | Incsub Hummingbird | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3. | |
| Modificada | Crítica (9.8) | 1.1% | — | Incsub Hummingbird | 10/4/2023 | 17/6/2026 | The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module. | |
| Modificada | Media (4.8) | 2.8% | — | Incsub Hummingbird | 18/4/2022 | 17/6/2026 | The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.8) | 6.9% | — | Hummingbird ExceedHummingbird Exceed Powersuite | 24/10/2008 | 16/6/2026 | Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0. | |
| Modificada | Alta (9.3) | 32% | — | Hummingbird Deployment Wizard | 24/10/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the… | |
| Modificada | Baja (3.5) | 1.1% | — | Hummingbird Enterprise Collaboration | 11/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting. | |
| Modificada | Media (4) | 2.8% | — | Hummingbird CollaborationHummingbird Enterprise Collaboration | 11/1/2006 | 16/6/2026 | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie. | |
| Modificada | Media (4) | 2.3% | — | Hummingbird Enterprise Collaboration | 11/1/2006 | 16/6/2026 | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content. | |
| Modificada | Alta (7.5) | 1.1% | — | Hummingbird Connectivity | 17/8/2005 | 16/6/2026 | Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges. | |
| Modificada | Media (5) | 47% | — | Hummingbird Connectivity | 1/6/2005 | 16/6/2026 | Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe). | |
| Modificada | Media (4.4) | 0.36% | — | Hummingbird Connectivity | 31/12/2004 | 16/6/2026 | Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections. | |
| Modificada | Baja (3.5) | 1.3% | — | Hummingbird Connectivity | 31/12/2004 | 16/6/2026 | Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command. | |
| Modificada | Baja (2.1) | 0.33% | — | Hummingbird Exceed | 31/12/2004 | 16/6/2026 | Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab. | |
| Modificada | Alta (7.5) | 1.5% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (5) | 1.8% | — | Hummingbird CyberdocsAIMicrosoft IISAI | 31/12/2003 | 16/6/2026 | Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code. | |
| Modificada | Media (4.3) | 1.5% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors. | |
| Modificada | Media (5) | 1.8% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message. | |
| Modificada | Media (5) | 1.3% | — | Hummingbird Exceed | 7/4/1999 | 16/6/2026 | Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000. | |
| Modificada | Alta (7.5) | 1.1% | — | Hummingbird Exceed | 3/12/1998 | 16/6/2026 | Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file. |