Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Infusedwoo PROAI | 25/8/2026 | 27/8/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users… | |
| Aplazada | Alta (7.5) | 0.46% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages,… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a… | |
| Aplazada | Alta (8.8) | 0.51% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible… | |
| Modificada | Alta (8.8) | 1.3% | — | Libconfuse Project LibconfuseFedoraproject Fedora | 9/9/2022 | 17/6/2026 | cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. | |
| Modificada | Alta (8.8) | 1.1% | — | Libconfuse Project Libconfuse | 30/11/2018 | 17/6/2026 | cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. | |
| Modificada | Alta (8.8) | 1.8% | — | Libconfuse Project LibconfuseDebian Linux | 20/7/2018 | 17/6/2026 | trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. | |
| Modificada | Alta (7.5) | 0.99% | — | Infuseum ASP Message Board | 7/11/2007 | 16/6/2026 | SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Citrix Metaframe Secure Access ManagerCitrix Nfuse | 3/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Alta (7.5) | 7.9% | — | Citrix Nfuse | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp. | |
| Modificada | Media (5) | 3.6% | — | Citrix Nfuse | 12/8/2002 | 16/6/2026 | Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | |
| Modificada | Media (5) | 2.5% | — | Citrix Nfuse | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter. | |
| Modificada | Media (5) | 2.0% | — | Citrix Nfuse | 31/5/2002 | 16/6/2026 | Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters. | |
| Modificada | Media (5) | 3.6% | — | Citrix Nfuse | 18/10/2001 | 16/6/2026 | Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field. |