Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.41% | — | Grashjs Atlas CmmsAI | 1/9/2026 | 2/9/2026 | A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Analizada | Crítica (9.3) | 0.88% | — | Ftnapps Crashmail II | 28/3/2026 | 17/6/2026 | Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of… | |
| Aplazada | Alta (8.1) | 0.47% | — | Goalthemes RashyAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Rashy rashy allows PHP Local File Inclusion.This issue affects Rashy: from n/a through <= 1.1.3. | |
| Aplazada | Media (5.3) | 0.27% | — | Solwininfotech Trash Duplicate AND 301 RedirectAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in solwininfotech Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through <= 1.9.1. | |
| Aplazada | Media (5.5) | 0.32% | — | Rashmindungrani Online-bankingAI | 7/12/2025 | 17/6/2026 | A vulnerability was found in RashminDungrani online-banking up to 2337ad552ea9d385b4e07b90e6f32d011b7c68a2. This affects an unknown part of the file /site/dist/auth_login.php. Performing manipulation of the argument Username results in sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.30% | — | G33kyrash Online-banking-systemAI | 17/11/2025 | 17/6/2026 | A vulnerability was detected in g33kyrash Online-Banking-System up to 12dbfa690e5af649fb72d2e5d3674e88d6743455. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit is now public and… | |
| Aplazada | Baja (3.3) | 0.19% | — | AMD Crash DefenderAI | 6/9/2025 | 17/6/2026 | Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality. | |
| Aplazada | Media (5.5) | 0.13% | — | AMD Crash DefenderAI | 6/9/2025 | 17/6/2026 | A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentially resulting in a system crash and loss of availability. | |
| Aplazada | Alta (7.1) | 0.24% | — | Ramanparashar UseinfluenceAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence useinfluence allows Stored XSS.This issue affects Useinfluence: from n/a through <= 1.0.8. | |
| Aplazada | Media (4.3) | 0.28% | — | Rashid Slider Path FOR ElementorAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Rashid Slider Path for Elementor slider-path allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Path for Elementor: from n/a through <= 3.0.0. | |
| Aplazada | Crítica (9.8) | 0.89% | — | Rashid DocproAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rashid Docpro docpro allows PHP Local File Inclusion.This issue affects Docpro: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.5) | 0.37% | — | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS ApplicationAI | 4/3/2025 | 17/6/2026 | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history,… | |
| Aplazada | Alta (7.5) | 0.54% | — | Trash Duplicate AND 301 RedirectAI | 19/2/2025 | 17/6/2026 | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages. | |
| Aplazada | Alta (7.1) | 0.28% | — | Arash Safari Qmean Wordpress DID YOU MeanAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Safari QMean – WordPress Did You Mean qmean allows Reflected XSS.This issue affects QMean – WordPress Did You Mean: from n/a through <= 2.0. | |
| Aplazada | Media (5.5) | 0.13% | — | AMD Crash DefenderAI | 12/2/2025 | 17/6/2026 | Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an operating system crash, potentially leading to denial of service. | |
| Aplazada | Media (6.5) | 0.32% | — | Arash Heidari Text AdvertisementsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Heidari Text Advertisements text-advertisements allows Stored XSS.This issue affects Text Advertisements: from n/a through <= 2.1. | |
| Modificada | Media (6.1) | 0.33% | — | Prashantmavinkurve Agile Video Player Lite | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woracal Agile Video Player Lite agile-video-player allows Reflected XSS.This issue affects Agile Video Player Lite: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.57% | — | Rashid87 WpsectionAI | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allows PHP Local File Inclusion.This issue affects WPSection: from n/a through 1.3.8. | |
| Aplazada | Media (5.9) | 0.44% | — | Rashed Latif TT Custom Post Type CreatorAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Custom Post Type Creator allows Stored XSS.This issue affects TT Custom Post Type Creator: from n/a through 1.0. | |
| Modificada | Alta (8.8) | 0.28% | — | Himanshuparashar Google Site Verification Plugin Using Meta TAG | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Himanshu Parashar Google Site Verification plugin using Meta Tag.This issue affects Google Site Verification plugin using Meta Tag: from n/a through 1.2. | |
| Modificada | Alta (8.8) | 0.28% | — | Walkeprashant WP ALL Backup | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prashant Walke WP All Backup plugin <= 2.4.3 versions. | |
| Modificada | Media (5.5) | 0.37% | — | Rashim Michlol | 5/8/2022 | 17/6/2026 | Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the… | |
| Modificada | Media (5.5) | 0.25% | — | Code42 FOR EnterpriseCode42 Crashplan FOR Small Business | 21/8/2019 | 17/6/2026 | In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write. | |
| Modificada | Alta (7) | 0.55% | — | Code42 FOR EnterpriseCode42 Crashplan FOR Small Business | 19/7/2019 | 17/6/2026 | Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user. |