Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.45% | — | HashtopolisAI | 17/7/2026 | 17/7/2026 | Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance. | |
| Analizada | Alta (8.8) | 0.42% | — | ORY Polis | 26/3/2026 | 17/6/2026 | Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting (XSS) vulnerability in Ory Polis's login functionality. The application improperly trusts a URL parameter (`callbackUrl`), which is passed… | |
| Analizada | Crítica (9.3) | 0.43% | — | Airship.ai Acropolis | 22/9/2025 | 17/6/2026 | Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gaining the privileges of this account. Fixed in 10.2.35, 11.0.21, and 11.1.9. | |
| Analizada | Alta (7.7) | 0.33% | — | Airship.ai Acropolis | 22/9/2025 | 17/6/2026 | Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9. | |
| Modificada | Media (4.3) | 0.38% | — | Mirapolis LMS | 12/9/2024 | 17/6/2026 | An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data. | |
| Modificada | Alta (7.5) | 1.2% | — | Autopolis Bulgarisation FOR Woocommerce | 13/3/2024 | 17/6/2026 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and… | |
| Modificada | Media (4.3) | 0.18% | — | Autopolis Bulgarisation FOR Woocommerce | 12/3/2024 | 17/6/2026 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged… | |
| Modificada | Media (4.8) | 0.39% | — | Interactive Polish MAP Project Interactive Polish MAP | 4/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcin Pietrzak Interactive Polish Map plugin <= 1.2 versions. | |
| Modificada | Alta (7.5) | 1.1% | — | Megacryptopolis | 6/8/2018 | 17/6/2026 | The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not… | |
| Modificada | Media (6.1) | 0.80% | — | Hashtopolis | 27/7/2017 | 17/6/2026 | Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) version, (2) url, or (3) rootdir parameter in hashcat.php. | |
| Modificada | Media (6.8) | 6.4% | — | Samsung Ipolis Device Manager | 24/2/2015 | 17/6/2026 | Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function. | |
| Modificada | Media (4.3) | 1.9% | — | Megapolis.portal Manager | 22/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Megapolis.Portal Manager allow remote attackers to inject arbitrary web script or HTML via the (1) dateFrom or (2) dateTo parameter. | |
| Modificada | Alta (9.3) | 5.6% | — | Samsung Ipolis Device Manager | 11/6/2014 | 17/6/2026 | Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control. | |
| Modificada | Alta (9.3) | 4.4% | — | Samsung Ipolis Device Manager | 5/6/2014 | 17/6/2026 | Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control in Samsung iPOLiS Device Manager before 1.8.7 allows remote attackers to execute arbitrary code via a long value. | |
| Modificada | Alta (7.5) | 0.97% | — | Joomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler | 6/5/2008 | 16/6/2026 | SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php. |