Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.10% | — | Real Estate PapiAI | 6/9/2026 | 8/9/2026 | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate ,… | |
| Aplazada | Media (5.3) | 0.47% | — | Shuanx BurpapifinderAI | 13/4/2025 | 17/6/2026 | A vulnerability has been found in shuanx BurpAPIFinder up to 2.0.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file BurpApiFinder.db. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Crítica (9) | 1.4% | — | Aruba PapiAI | 5/11/2024 | 17/6/2026 | Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute… | |
| Aplazada | Crítica (9.8) | 2.0% | — | Aruba PapiAI | 5/11/2024 | 17/6/2026 | Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Aruba PapiAI | 25/9/2024 | 17/6/2026 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Aruba PapiAI | 25/9/2024 | 17/6/2026 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute… | |
| Aplazada | Crítica (9.8) | 15% | — | Aruba PapiAI | 1/5/2024 | 17/6/2026 | There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this… | |
| Aplazada | Crítica (9.8) | 15% | — | Aruba Automatic Reporting ServiceAIAruba PapiAI | 1/5/2024 | 17/6/2026 | There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in… | |
| Aplazada | Crítica (9.8) | 44% | — | Aruba PapiAI | 1/5/2024 | 17/6/2026 | There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the… | |
| Modificada | Media (6.4) | 1.6% | — | ACD Incorporated Cwpapi | 16/5/2002 | 16/6/2026 | GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root. |