Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | If-so Dynamic Content PersonalizationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. | |
| Aplazada | Alta (7.1) | 0.80% | — | Personal-management-system Personal Management SystemAI | 27/8/2026 | 24/9/2026 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against… | |
| Aplazada | Crítica (9.3) | 0.40% | — | If-so Dynamic Content PersonalizationAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | |
| Aplazada | Crítica (9.8) | 0.83% | — | Personal QR MessageAI | 3/8/2026 | 26/8/2026 | The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution. | |
| Aplazada | Alta (8.5) | 0.11% | — | Mobaxterm Personal EditionAI | 12/6/2026 | 17/6/2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. Because the application automatically loads the winspool.drv library from that location during startup, an attacker with local… | |
| Aplazada | Alta (8.5) | 0.11% | — | Mobaxterm Personal EditionAI | 12/6/2026 | 17/6/2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s… | |
| Aplazada | Alta (7.1) | 0.22% | — | Single Personal MessageAI | 9/6/2026 | 21/7/2026 | Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive… | |
| Pendiente de análisis | Alta (8.6) | 0.60% | — | Lenovo Personal Cloud StorageAI | 13/5/2026 | 17/6/2026 | A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device. | |
| Pendiente de análisis | Alta (8.7) | 0.84% | — | Lenovo Personal Cloud StorageAI | 13/5/2026 | 17/6/2026 | A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device. | |
| Aplazada | Baja (2.1) | 1.8% | — | Danielmiessler Personal AI InfrastructureAI | 13/4/2026 | 17/6/2026 | A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (6.1) | 0.21% | — | Personal-authors-categoryAI | 14/2/2026 | 17/6/2026 | The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (8.5) | 0.17% | — | Intego Personal BackupAI | 12/2/2026 | 17/6/2026 | Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-privileged users while being processed with elevated privileges. By crafting a… | |
| Analizada | Baja (2) | 0.29% | — | Rems Personal Time Tracker | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Media (6.5) | 0.21% | — | If-so Dynamic Content PersonalizationAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.4. | |
| Aplazada | Media (6.5) | 0.19% | — | If-so Dynamic Content PersonalizationAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.3.1. | |
| Aplazada | Alta (7.1) | 0.15% | — | Mangup Personal FaviconAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue affects Personal Favicon: from n/a through <= 2.0. | |
| Analizada | Media (5.4) | 0.30% | — | If-so Dynamic Content Personalization | 15/5/2025 | 17/6/2026 | The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.8) | 2.0% | — | Pwsdashboard Personal Weather Station DashboardAI | 7/5/2025 | 17/6/2026 | Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext. | |
| Analizada | Media (4.8) | 0.35% | — | Fabian Personal Diary Management System | 28/4/2025 | 17/6/2026 | A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the component New Record Handler. The manipulation of the argument filename leads to stack-based buffer overflow. Local access is required to approach this… | |
| Aplazada | Media (5.4) | 0.22% | — | Personal-management-system Personal Management SystemAI | 22/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter. | |
| Aplazada | Media (5.4) | 0.22% | — | Personal-management-system Personal Management SystemAI | 22/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter. | |
| Analizada | Media (4.7) | 0.21% | — | Personal-management-system Personal Management System | 18/4/2025 | 17/6/2026 | Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function. | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component. | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function. |