Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
1917 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | — | — | Tp-link Deco M9 PlusAI | 1/10/2026 | 1/10/2026 | A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated… | |
| Pendiente de análisis | Media (5.3) | 0.42% | — | AJA Helo PlusAI | 30/9/2026 | 1/10/2026 | AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw… | |
| Aplazada | Alta (8.7) | 0.51% | — | AJA Helo PlusAI | 30/9/2026 | 30/9/2026 | AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image… | |
| Aplazada | Media (6.5) | 0.22% | — | THE Plus AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wppa WP Photo Album PlusAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | |
| Aplazada | Alta (8.7) | 0.30% | — | Nicotine-plus Nicotine+AI | 29/9/2026 | 30/9/2026 | Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11. | |
| Aplazada | Alta (8.8) | 0.40% | — | Convertplug ConvertplusAI | 28/9/2026 | 29/9/2026 | The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the… | |
| Aplazada | Alta (8.8) | 0.27% | — | Bimser EBA PlusAI | 28/9/2026 | 28/9/2026 | Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11. | |
| Aplazada | Media (5.4) | 0.15% | — | Bimser EBA PlusAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11. | |
| Aplazada | Media (6.5) | 0.29% | — | Bimser EBA PlusAI | 28/9/2026 | 28/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11. | |
| Aplazada | Alta (7.7) | 0.80% | — | EyeplusAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.29% | — | EyeplusAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.29% | — | EyeplusAI | 28/9/2026 | 28/9/2026 | A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.3) | 0.19% | — | UpdraftplusAI | 27/9/2026 | 28/9/2026 | The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration… | |
| Aplazada | Media (6.4) | 0.19% | — | Wordplus Better MessagesAI | 25/9/2026 | 25/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.27% | — | Wordplus Better MessagesAI | 25/9/2026 | 25/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Pendiente de análisis | Alta (8.5) | 1.0% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 25/9/2026 | 30/9/2026 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write… | |
| Aplazada | Alta (7.1) | 0.19% | — | Wppa WP Photo Album PlusAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. | |
| Aplazada | Media (6.5) | 0.19% | — | Payplus Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| Pendiente de análisis | Alta (8.6) | 1.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 22/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. | |
| Pendiente de análisis | Crítica (9.8) | 4.6% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 23/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | |
| Aplazada | Media (6.5) | 0.70% | — | Wordplus Better MessagesAI | 19/9/2026 | 21/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.56% | — | Wordplus Better MessagesAI | 19/9/2026 | 21/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check… | |
| Aplazada | Alta (7.5) | 0.91% | — | Wppa WP Photo Album PlusAI | 19/9/2026 | 21/9/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd()… | |
| Pendiente de análisis | Alta (7.7) | 1.5% | — | Manageengine Datasecurity PlusAI | 18/9/2026 | 18/9/2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module. |