Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.28% | — | Fahadmahmood Endless Posts NavigationAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Endless Posts Navigation: from n/a through <= 2.2.9. | |
| Aplazada | Media (4.3) | 0.13% | — | WPM Navigation Links FOR Sections AND HeadingsAI | 4/11/2025 | 17/6/2026 | The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it possible for… | |
| Modificada | Alta (7.3) | 0.25% | — | Hyundai Navigation | 27/8/2025 | 5/7/2026 | In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered. | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpdistillery Navigation Tree ElementorAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdistillery Navigation Tree Elementor navigation-tree-elementor allows Blind SQL Injection.This issue affects Navigation Tree Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Cornershop Better Section Navigation WidgetAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cornershop Better Section Navigation Widget better-section-navigation allows Stored XSS.This issue affects Better Section Navigation Widget: from n/a through <= 1.6.1. | |
| Aplazada | Media (5.9) | 0.35% | — | Jenst Mobile NavigationAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jenst Mobile Navigation mobile-navigation allows Stored XSS.This issue affects Mobile Navigation: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.28% | — | Bjoerne Navigation DU Lapin BlancAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bjoerne Navigation Du Lapin Blanc navigation-du-lapin-blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.3) | 0.30% | — | Open Robotic Ros2AIOpen Robotic Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process. | |
| Aplazada | Alta (7.3) | 0.31% | — | Open Robotic Operating System Ros2AIOpen Robotic Operating System Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process | |
| Aplazada | Alta (7.8) | 0.22% | — | Openrobotics Robotic Operating System 2AIOpenrobotics Navigation2AI | 5/12/2024 | 17/6/2026 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator | |
| Aplazada | Alta (7.8) | 0.23% | — | Openrobotics Robotic Operating System 2AIOpenrobotics Navigation2AI | 5/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script. | |
| Aplazada | Alta (7.1) | 0.17% | — | Zajax Ajax NavigationAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Zajax – Ajax Navigation zajax-ajax-navigation allows Stored XSS.This issue affects Zajax – Ajax Navigation: from n/a through <= 0.4. | |
| Modificada | Media (6.1) | 0.17% | — | Androidbubbles Endless Posts Navigation | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through <= 2.2.7. | |
| Aplazada | Media (5.3) | 0.42% | — | Admin Post NavigationAI | 27/7/2024 | 17/6/2026 | The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Aplazada | Media (5.9) | 0.34% | — | Jeroen Peters Navigation Menu AS Dropdown WidgetAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navigation menu as Dropdown Widget navigation-menu-as-dropdown-widget.This issue affects Navigation menu as Dropdown Widget: from n/a through <= 1.3.4. | |
| Modificada | Alta (7.5) | 12% | — | Stagil Navigation | 28/2/2023 | 17/6/2026 | An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system. | |
| Modificada | Alta (7.5) | 47% | — | Stagil Navigation | 28/2/2023 | 17/6/2026 | An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system. | |
| Modificada | Media (5.4) | 0.27% | — | Baidu Navigation | 19/10/2014 | 17/6/2026 | The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |