Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.43% | — | Themeton THE Barber ShopAI | 17/6/2026 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Themeton FinagAI | 19/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themeton ZuutAI | 19/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Themeton Consult AIDAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themeton Seven StarsAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Seven Stars allows Stored XSS. This issue affects Seven Stars: from n/a through 1.4.4. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Themeton SpareAI | 17/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7. | |
| Aplazada | Alta (7.1) | 0.28% | — | Themeton SpareAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Spare allows Reflected XSS. This issue affects Spare: from n/a through 1.7. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Pressgrid - Frontend Publish Reaction & Multimedia ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3.1. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Pimp - Creative MultipurposeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative MultiPurpose: from n/a through 1.7. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Flap - Business Wordpress ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Business WordPress Theme: from n/a through 1.5. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Themeton THE Fashion - Model Agency ONE Page Beauty ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This issue affects The Fashion - Model Agency One Page Beauty Theme: from n/a through <= 1.4.4. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton AcerolaAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola: from n/a through 1.6.5. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton THE BusinessAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Hotstar - Multi-purpose Business ThemeAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton DashAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Themeton SpareAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7. | |
| Aplazada | Media (5.3) | 0.32% | — | Themeton THE BusinessAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Business: from n/a through 1.6.1. | |
| Aplazada | Media (5.3) | 0.31% | — | Themeton Hotstar Multi Purpose Business ThemeAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4. | |
| Aplazada | Media (4.3) | 0.20% | — | Themeton Seven StarsAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4. | |
| Aplazada | Media (5.3) | 0.41% | — | Themeton AcerolaAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acerola: from n/a through <= 1.6.5. | |
| Aplazada | Media (5.3) | 0.31% | — | Themeton RozarioAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rozario: from n/a through 1.4. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Daenetip4 MetoAI | 18/4/2025 | 17/6/2026 | Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack. | |
| Aplazada | Alta (7.1) | 0.25% | — | Awesometogi Awesome Event BookingAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Reflected XSS.This issue affects Awesome Event Booking: from n/a through <= 2.8.4. | |
| Aplazada | Media (6.5) | 0.36% | — | Awesometogi Awesome Event BookingAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Event Booking: from n/a through <= 2.7.2. | |
| Aplazada | Alta (7.1) | 0.14% | — | Stanko Metodiev Quote-commentsAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This issue affects Quote Comments: from n/a through <= 3.0.0. |