Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.63% | — | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message… | |
| Analizada | Crítica (9.3) | 0.63% | — | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Tugcantopaloglu Godot-mcpAI | 13/7/2026 | 13/7/2026 | A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Attacking locally is a requirement. The exploit has been… | |
| Aplazada | Alta (7.5) | 0.45% | — | Opal WP FashionAIPHPAI | 9/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Opal_WP Fashion fashion2 allows PHP Local File Inclusion.This issue affects Fashion: from n/a through < 5.3.0. | |
| Aplazada | Alta (7.5) | 0.45% | — | Opal WP EkommartAI | 9/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Opal_WP ekommart ekommart allows PHP Local File Inclusion.This issue affects ekommart: from n/a through < 4.3.1. | |
| Analizada | Alta (7.5) | 0.34% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure. | |
| Analizada | Crítica (9.9) | 0.72% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary files under certain conditions. | |
| Analizada | Media (5.3) | 0.22% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values. | |
| Analizada | Alta (7.5) | 0.28% | — | Desktopalert Pingalert Application Server | 24/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes. | |
| Analizada | Media (4.3) | 0.22% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace. | |
| Analizada | Media (4.3) | 0.20% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content despite lack of the correct permission through a Broken Authorization Schema. | |
| Analizada | Baja (3.8) | 0.19% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure. | |
| Analizada | Baja (3.7) | 0.28% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content. | |
| Analizada | Media (6.5) | 0.17% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information. | |
| Analizada | Alta (7.6) | 0.25% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information. | |
| Analizada | Alta (7.5) | 0.30% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthorized Actor. | |
| Analizada | Crítica (9.6) | 0.26% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Analizada | Baja (3.3) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies. | |
| Analizada | Media (4.1) | 0.09% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm. | |
| Analizada | Crítica (10) | 0.31% | — | Desktopalert Pingalert Application Server | 14/11/2025 | 17/6/2026 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges. | |
| Aplazada | Media (6.5) | 0.20% | — | Wpopal Opal ServiceAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpopal Opal Service opal-service allows Stored XSS.This issue affects Opal Service: from n/a through <= 1.9.1. | |
| Aplazada | Crítica (10) | 0.56% | — | Topal Solutions AG Topal FinanzbuchhaltungAI | 6/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and is fixed in version 11.2.12.00 | |
| Aplazada | Crítica (9.8) | 28% | — | Opal Estate PROAI | 1/7/2025 | 17/6/2026 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user'… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpopal GG Bought TogetherAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought Together for WooCommerce gg-bought-together allows SQL Injection.This issue affects GG Bought Together for WooCommerce: from n/a through <= 1.0.2. | |
| Analizada | Media (6.9) | 0.58% | — | Lopalopa Responsive Online Learing Platform | 27/5/2025 | 17/6/2026 | A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The… |