Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.20% | — | Morning-pro MorningAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. | |
| Aplazada | Alta (8.1) | 0.40% | — | Ancoththemes Morning RecordsAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Records: from n/a through <= 1.2. | |
| Analizada | Media (5.5) | 0.61% | — | Morning-pro Morning | 10/8/2025 | 17/6/2026 | A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown function of the file /index of the component Shiro Configuration. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (6.5) | 0.22% | — | Victortihai Morningtime LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in victortihai MorningTime Lite morningtime-lite allows Stored XSS.This issue affects MorningTime Lite: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.25% | — | CAT Ning MorningAI | 17/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (6.1) | 0.85% | — | Morningstarsecurity Whatweb | 30/8/2018 | 17/6/2026 | MorningStar WhatWeb 0.4.9 has XSS via JSON report files. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Adazing Morning Coffee | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. |