Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Spectra LegacyAI | 24/9/2026 | 24/9/2026 | The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it… | |
| Aplazada | Baja (3.5) | 0.15% | — | Spectra LegacyAI | 1/8/2026 | 26/8/2026 | The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into the pages that render the affected block. The injected styles are… | |
| Aplazada | Crítica (9.4) | 0.34% | — | Ellucian Advance WEBAIEllucian Advance LegacyAI | 28/7/2026 | 9/9/2026 | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Aplazada | Alta (7.1) | 0.18% | — | Themepassion Legacy AdminAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows Reflected XSS.This issue affects Legacy Admin: from n/a through <= 9.5. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Legacy | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Legacy legacy allows PHP Local File Inclusion.This issue affects Legacy: from n/a through <= 1.9. | |
| Aplazada | Media (5.5) | 0.50% | 💥 PoC | Esapi-java-legacyAI | 29/6/2025 | 17/6/2026 | A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an exploit has been disclosed to the… | |
| Aplazada | Media (6.5) | 0.28% | — | Brian Legacy EplayerAISportspress TVAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Legacy ePlayer sportspress-tv allows Stored XSS.This issue affects Legacy ePlayer: from n/a through <= 0.9.9. | |
| Analizada | Alta (7.8) | 0.24% | — | WUT COM Port Redirector LegacyWUT COM Port Redirector Plug & PlayWUT OPC Server | 1/3/2024 | 17/6/2026 | A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+2 | 27/10/2023 | 17/6/2026 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or… | |
| Modificada | Media (5.4) | 0.35% | — | Ravanh Skype Legacy Buttons | 20/10/2023 | 17/6/2026 | The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.49% | — | Ibexa Ezpublish LegacyIbexa Ezpublish Platform | 26/6/2023 | 17/6/2026 | Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the video-js.swf. | |
| Modificada | Alta (7.5) | 1.2% | — | Opcfoundation UA Java LegacyProsysopc UA HistorianProsysopc UA Modbus ServerProsysopc UA Simulation Server | 15/5/2023 | 17/6/2026 | The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications. | |
| Modificada | Alta (7.5) | 0.59% | — | Gitter EZ Publish Modern Legacy | 19/1/2023 | 17/6/2026 | A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak password recovery. The complexity of an attack is rather high. The exploitation is known to be… | |
| Modificada | Media (6.1) | 0.84% | — | Concrete5-legacy Project Concrete5-legacy | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Concrete5-legacy Project Concrete5-legacy | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the rel parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Concrete5-legacy Project Concrete5-legacy | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the cID parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Concrete5-legacy Project Concrete5-legacy | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the ctID parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Concrete5-legacy Project Concrete5-legacy | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote attackers to inject arbitrary web script or HTML via the mode parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Opcfoundation Ua-.net-legacyOpcfoundation UA .net Standard Stack | 20/5/2021 | 17/6/2026 | OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow. | |
| Modificada | Media (6.1) | 0.83% | — | Teradici Cloud Access ConnectorTeradici Cloud Access Connector Legacy | 11/8/2020 | 17/6/2026 | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16 and earlier for the Cloud Access Connector) contains a stored cross-site scripting (XSS) vulnerability which allows a remote unauthenticated attacker to poison log files with… | |
| Modificada | Alta (7.5) | 1.7% | — | Teradici Cloud Access ConnectorTeradici Cloud Access Connector Legacy | 11/8/2020 | 17/6/2026 | The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially… | |
| Modificada | Crítica (9.8) | 2.3% | — | EZ Publish-kernelEZ Publish-legacy | 22/3/2020 | 17/6/2026 | eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Import Legacy Media Project Import Legacy Media | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php. |