Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

1917 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)——Tp-link Deco M9 PlusAI1/10/20261/10/2026
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated…
Pendiente de análisisMedia (5.3)0.42%—AJA Helo PlusAI30/9/20261/10/2026
AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw…
AplazadaAlta (8.7)0.51%—AJA Helo PlusAI30/9/202630/9/2026
AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image…
AplazadaMedia (6.5)0.22%—THE Plus AddonsAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.
AplazadaMedia (6.5)0.22%—Wppa WP Photo Album PlusAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
AplazadaAlta (8.7)0.30%—Nicotine-plus Nicotine+AI29/9/202630/9/2026
Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.
AplazadaAlta (8.8)0.40%—Convertplug ConvertplusAI28/9/202629/9/2026
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the…
AplazadaAlta (8.8)0.27%—Bimser EBA PlusAI28/9/202628/9/2026
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
AplazadaMedia (5.4)0.15%—Bimser EBA PlusAI28/9/202628/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
AplazadaMedia (6.5)0.29%—Bimser EBA PlusAI28/9/202628/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
AplazadaAlta (7.7)0.80%—EyeplusAI28/9/202628/9/2026
A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
AplazadaMedia (5.5)0.29%—EyeplusAI28/9/20261/10/2026
A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.29%—EyeplusAI28/9/202628/9/2026
A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.
AplazadaMedia (5.3)0.19%—UpdraftplusAI27/9/202628/9/2026
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration…
AplazadaMedia (6.4)0.19%—Wordplus Better MessagesAI25/9/202625/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.5)0.27%—Wordplus Better MessagesAI25/9/202625/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
Pendiente de análisisAlta (8.5)1.0%—Netgate Pfsense PlusAINetgate Pfsense CEAI25/9/202630/9/2026
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write…
AplazadaAlta (7.1)0.19%—Wppa WP Photo Album PlusAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
AplazadaMedia (6.5)0.19%—Payplus Payment GatewayAI23/9/202623/9/2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
Pendiente de análisisAlta (8.6)1.7%—Zohocorp Manageengine Adselfservice PlusAI22/9/202622/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Pendiente de análisisCrítica (9.8)4.6%—Zohocorp Manageengine Adselfservice PlusAI22/9/202623/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
AplazadaMedia (6.5)0.70%—Wordplus Better MessagesAI19/9/202621/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (5.3)0.56%—Wordplus Better MessagesAI19/9/202621/9/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check…
AplazadaAlta (7.5)0.91%—Wppa WP Photo Album PlusAI19/9/202621/9/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd()…
Pendiente de análisisAlta (7.7)1.5%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.