Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.94% | — | 2100 Technology Official Document Management SystemAI | 17/8/2026 | 26/8/2026 | Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Official Owasp ZAP | 24/6/2026 | 26/6/2026 | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |
| Aplazada | Crítica (9.1) | 0.27% | — | EPG INC Kura Sushi Official APPAI | 12/5/2026 | 17/6/2026 | "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server. | |
| Analizada | Media (6.9) | 0.15% | — | Tomalofficial PHP OOP CMS Blog | 6/3/2026 | 17/6/2026 | OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can submit forms to the addUser.php endpoint with parameters including userName, password, email, and role set to… | |
| Analizada | Alta (8.8) | 0.36% | — | Tomalofficial PHP OOP CMS Blog | 6/3/2026 | 17/6/2026 | OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to… | |
| Aplazada | Media (4.3) | 0.25% | — | Official-mailerlite-sign-up-formsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18. | |
| Aplazada | Alta (7.1) | 0.29% | — | 2100 Technology Official Document Management SystemAI | 28/1/2026 | 17/6/2026 | Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to modify front-end code to read all official documents. | |
| Aplazada | Media (5.4) | 0.24% | — | Monetag OfficialAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Monetag Official Plugin: from n/a through <= 1.1.3. | |
| Analizada | Alta (7.5) | 0.30% | — | Wanliofficial Lvzhou CMS | 2/12/2025 | 17/6/2026 | Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.lvzhoucms.service.ContentService#findPage. The parameter is concatenated directly into a dynamic SQL query without sanitization or prepared statements, enabling attackers… | |
| Aplazada | Alta (7.2) | 0.48% | — | Official Integration FOR BillingoAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official Integration for Billingo: from n/a through <= 4.3.0. | |
| Aplazada | Crítica (9.3) | 0.71% | — | 2100 Technology Official Document Management SystemAI | 11/8/2025 | 17/6/2026 | Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user. | |
| Aplazada | Media (4.3) | 0.33% | — | Timelineofficial Time-lineAI | 15/7/2025 | 17/6/2026 | The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found in the TIME LINE website where uploaded files (instruction/message media) are not strictly validated for type and size. A user may upload renamed or oversized files that can disrupt performance or… | |
| Aplazada | Media (5.4) | 0.16% | — | Nghialuu Zalo Official Live ChatAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat zalo-official-live-chat allows Cross Site Request Forgery.This issue affects Zalo Official Live Chat: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Official Cleverreach Plugin FOR WoocommerceAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce cleverreach-wc allows Cross Site Request Forgery.This issue affects Official CleverReach Plugin for WooCommerce: from n/a through <= 3.4.6. | |
| Aplazada | Media (6.5) | 0.29% | — | Fiverraffiliates Fiverr-official-search-boxAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fiverraffiliates Fiverr.com Official Search Box fiverr-official-search-box allows Stored XSS.This issue affects Fiverr.com Official Search Box: from n/a through <= 1.0.8. | |
| Aplazada | Alta (7.6) | 0.45% | — | Jiangqie Official Website Mini ProgramAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jiangqie JiangQie Official Website Mini Program jiangqie-official-website-mini-program allows Blind SQL Injection.This issue affects JiangQie Official Website Mini Program: from n/a through <= 1.8.2. | |
| Modificada | Crítica (9.8) | 1.4% | — | Keap Official OPT IN Forms | 18/2/2025 | 17/6/2026 | The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be… | |
| Aplazada | Alta (7.2) | 0.41% | — | Monetag OfficialAI | 14/2/2025 | 17/6/2026 | Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Monetag Official Plugin: from n/a through <= 1.1.3. | |
| Aplazada | Crítica (9.8) | 1.3% | — | 2100 Technology Electronic Official Document Management SystemAI | 31/12/2024 | 17/6/2026 | The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be… | |
| Aplazada | Alta (7.5) | 0.58% | — | Officialprocoders NblocksAI | 20/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in officialprocoders nBlocks nblocks allows PHP Local File Inclusion.This issue affects nBlocks: from n/a through <= 1.0.2. | |
| Aplazada | Media (4) | 0.15% | — | Epark Kura Sushi Official APPAI | 20/11/2024 | 17/6/2026 | Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If this vulnerability is exploited, a local attacker may obtain the login ID and password for the affected product. | |
| Aplazada | Media (6.5) | 0.32% | — | Official Saleswizard CRMAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SalesWizard.pl Official SalesWizard CRM Plugin official-saleswizard-crm allows Stored XSS.This issue affects Official SalesWizard CRM Plugin: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.16% | — | Platformly OfficialAI | 14/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Official: from n/a through <= 1.1.3. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Alexander DE Ridder INK OfficialAI | 23/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Upload a Web Shell to a Web Server.This issue affects INK Official: from n/a through <= 4.1.2. | |
| Aplazada | Media (6.5) | 0.26% | — | Keap Official Opt-in FormsAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official Opt-in Forms infusionsoft-official-opt-in-forms allows Stored XSS.This issue affects Keap Official Opt-in Forms: from n/a through <= 2.0.3. |