Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.59% | — | Rtgs2017 NagaagentAI | 5/5/2026 | 17/6/2026 | A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.py of the component Skills Endpoint. Such manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (4.3) | 0.12% | — | Kunalnagar Custom 404 PROAI | 22/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= 3.12.0. | |
| Aplazada | Media (4.9) | 0.30% | — | Kunalnagar Custom 404 PROAI | 11/10/2025 | 17/6/2026 | The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.15% | — | Nagarjunsonti MY Login LogoutAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS.This issue affects My Login Logout Plugin: from n/a through <= 2.4. | |
| Modificada | Media (6.1) | 0.62% | — | Kunalnagar Custom 404 PRO | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1. | |
| Analizada | Crítica (9.8) | 0.66% | — | Gfx-rs WgpuGfx-rs Naga | 12/6/2024 | 17/6/2026 | naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs. | |
| Modificada | Media (6.1) | 0.35% | — | Kunalnagar Custom 404 PRO | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro: from n/a through 3.10.0. | |
| Modificada | Alta (8.2) | 0.58% | — | Linecorp Fukunaga Memberscard | 25/10/2023 | 17/6/2026 | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | |
| Modificada | Media (6.5) | 0.46% | — | Youmart-tokunaga Project Youmart-tokunaga | 18/9/2023 | 9/7/2026 | An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Media (6.1) | 0.34% | — | Kunalnagar Custom 404 PRO | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.8.1 versions. | |
| Modificada | Crítica (9.8) | 0.93% | — | Kunalnagar Custom 404 PRO | 27/6/2023 | 17/6/2026 | The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities. | |
| Modificada | Media (6.1) | 1.7% | — | Kunalnagar Custom 404 PRO | 30/5/2023 | 17/6/2026 | The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | |
| Modificada | Alta (7.2) | 0.67% | — | Kunalnagar Custom 404 PRO | 12/4/2023 | 17/6/2026 | Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions. | |
| Modificada | Media (4.3) | 0.32% | — | Kunalnagar Custom 404 PRO | 18/1/2023 | 17/6/2026 | The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for unauthenticated attackers to delete logs, via forged request granted… | |
| Modificada | Alta (7.4) | 1.2% | — | 77bank 77 BankAshikagabank AshiginHokkaidobank DoginHokugin Hokuriku Bank Portal+5 | 28/1/2020 | 17/6/2026 | Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (6.1) | 0.95% | — | Kunalnagar Custom 404 PRO | 30/8/2019 | 17/6/2026 | The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. | |
| Modificada | Media (6.1) | 1.6% | — | Kunalnagar Custom 404 PRO | 15/8/2019 | 17/6/2026 | The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter. | |
| Modificada | Media (6.1) | 1.5% | — | Kinagacms Project Kinagacms | 27/3/2019 | 17/6/2026 | Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Gfx-rs Naga | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for naga, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Baja (3.5) | 0.87% | — | Astha Bhatnagar Shindigintegrator | 31/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the OpenSocial Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a module for Drupal, allows remote authenticated users, with "create application" privileges, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 11% | — | Chinagames Igame | 28/5/2009 | 16/6/2026 | Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are… | |
| Modificada | Media (5) | 1.4% | — | Hisanaga Electric CO Hisa Cart | 21/10/2008 | 16/6/2026 | Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors. |