Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.30% | — | Wptools Extra Product OptionsAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | |
| Analizada | Media (6.1) | 0.40% | — | Python Setuptools | 8/7/2026 | 13/7/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so… | |
| Aplazada | Alta (8.8) | 0.42% | — | Wptools Abandoned Cart PROAI | 26/6/2026 | 26/6/2026 | Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Wptools MotorsAI | 14/5/2026 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary… | |
| Aplazada | Baja (2.1) | 0.43% | — | Zachhandley ZmcptoolsAI | 30/4/2026 | 17/6/2026 | A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path traversal. Remote exploitation of the… | |
| Analizada | Alta (7.7) | 1.5% | — | Python SetuptoolsDebian Linux | 17/5/2025 | 17/6/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of… | |
| Aplazada | Alta (7.1) | 0.23% | — | Androidapptools Easy FilterAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roni Saha Easy Filter easy-filter allows Reflected XSS.This issue affects Easy Filter: from n/a through <= 1.10. | |
| Aplazada | Alta (8.8) | 1.9% | — | Pypa SetuptoolsAI | 15/7/2024 | 17/6/2026 | A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these… | |
| Modificada | Media (5.5) | 0.17% | — | Steptools Ifcmesh Library | 13/3/2023 | 17/6/2026 | STEPTools v18SP1 ifcmesh library (v18.1) is affected due to a null pointer dereference, which could allow an attacker to deny application usage when reading a specially constructed file, resulting in an application crash. | |
| Modificada | Media (5.9) | 2.5% | — | Python Setuptools | 23/12/2022 | 17/6/2026 | Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py. | |
| Modificada | Media (5.7) | 0.44% | — | Wptools Project Wptools | 12/12/2022 | 17/6/2026 | The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary… | |
| Modificada | Media (6.8) | 2.0% | — | Python Setuptools | 6/8/2013 | 16/6/2026 | easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product. | |
| Modificada | Media (5) | 2.5% | — | Kepler LAM Iptools | 9/10/2012 | 16/6/2026 | Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service (crash) via a long string to TCP port 23. | |
| Modificada | Media (5) | 7.2% | — | Kepler LAM Iptools | 9/10/2012 | 16/6/2026 | Directory traversal vulnerability in the WebServer (Thttpd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a HTTP request. | |
| Modificada | Media (6.4) | 1.0% | — | Androidapptools Easy Filter | 25/1/2012 | 16/6/2026 | The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application. | |
| Modificada | Media (5) | 1.2% | — | Maptools Ka-map | 23/9/2011 | 16/6/2026 | ka-Map 1.0-20070205 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test.php and certain other files. | |
| Modificada | Media (6.8) | 3.3% | — | Maptools Maplab | 3/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Parallel Tools Consortium Ptools | 23/12/2005 | 16/6/2026 | SQL injection vulnerability in index.asp in pTools allows remote attackers to execute arbitrary SQL commands via the docID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 9.7% | — | HP Instant Toptools | 11/4/2003 | 16/6/2026 | hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop. | |
| Modificada | Alta (7.2) | 1.2% | — | Plptools | 19/2/2003 | 16/6/2026 | Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog. |