Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
–

1234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.1)0.21%—Wpclever WPC Estimated Delivery DateAI3/10/20263/10/2026
The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.8)0.38%—GO Live Update UrlsAI30/9/202630/9/2026
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
AplazadaMedia (6.8)0.18%—Bishopfox SliverAI29/9/202630/9/2026
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads…
Pendiente de análisisMedia (5.6)0.09%—Dell Live Optics CollectorAI28/9/202628/9/2026
Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to…
ModificadaAlta (7)0.24%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression…
AnalizadaCrítica (9.3)0.36%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before…
AnalizadaCrítica (9.5)1.3%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202628/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
AnalizadaCrítica (9.5)1.1%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute…
AplazadaAlta (8.5)0.21%—Live Copy PasteAI23/9/202623/9/2026
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
AplazadaMedia (6.4)0.22%—Live ComposerAI22/9/202622/9/2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (4.3)0.60%—Datalogics Ecommerce DeliveryAI19/9/202621/9/2026
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Service Delivery PlatformAI15/9/202616/9/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Service Delivery PlatformAI15/9/202616/9/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.…
Pendiente de análisisCrítica (9.9)0.42%—Oracle Service Delivery PlatformAI15/9/202616/9/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.…
Pendiente de análisisCrítica (9.9)0.42%—Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI15/9/202616/9/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery…
Pendiente de análisisCrítica (9.9)0.42%—Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI15/9/202616/9/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery…
AplazadaMedia (4.1)0.15%—Live-bootAI11/9/202622/9/2026
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
AplazadaCrítica (9.3)0.37%—Avideo LivelinksAIWwbn AvideoAI10/9/202610/9/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor…
Pendiente de análisisMedia (6.5)0.44%—Live555 Streaming MediaAI9/9/202614/9/2026
A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.
AplazadaAlta (8.8)0.45%—Live ComposerAI8/9/20268/9/2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserialization of untrusted input . This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No…
AplazadaMedia (5.5)0.50%—Itsourcecode Online Medicine Delivery SystemAI3/9/20264/9/2026
A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument image results in unrestricted upload. Remote…