Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.26% | — | F-revocrmAI | 20/8/2026 | 28/8/2026 | F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed. | |
| Aplazada | Media (5.3) | 0.31% | — | Revolut Gateway FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | |
| Aplazada | Crítica (10) | 0.52% | — | Coderevolution Aimogen PROAI | 13/7/2026 | 13/7/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3. | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Themepunch Slider RevolutionAI | 2/7/2026 | 2/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16. | |
| Aplazada | Alta (7.1) | 0.14% | — | VS Revo RevouninstallerAI | 15/6/2026 | 24/7/2026 | A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and… | |
| Aplazada | Media (6.5) | 0.42% | — | Themepunch Slider RevolutionAI | 9/6/2026 | 23/7/2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the… | |
| Aplazada | Media (4.3) | 0.26% | — | Themepunch Slider RevolutionAI | 2/6/2026 | 22/7/2026 | The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.3) | 0.28% | — | Themepunch Slider RevolutionAI | 2/6/2026 | 22/7/2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API… | |
| Aplazada | Media (5.3) | 0.36% | — | Themepunch Slider RevolutionAI | 20/5/2026 | 24/7/2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content. | |
| Aplazada | Alta (8.8) | 0.79% | — | Themepunch Slider RevolutionAI | 7/5/2026 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Aplazada | Media (6.5) | 0.48% | — | BrevoAI | 18/2/2026 | 17/6/2026 | The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type juggling in all versions up to, and including, 3.3.0. This is due to the use of loose comparison (==) instead of strict comparison (===) when validating the installation ID in the… | |
| Aplazada | Alta (7.2) | 0.30% | — | Brevo FOR WoocommerceAI | 8/1/2026 | 17/6/2026 | The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’ parameter in all versions up to, and including, 4.0.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Alta (7.5) | 0.51% | — | Revotech I6032w-fhw Firmware | 2/1/2026 | 5/7/2026 | An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attackers to access sensitive information and escalate privileges via a crafted HTTP request. | |
| Aplazada | Media (5.3) | 0.25% | — | Brevo Sendinblue FOR WoocommerceAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Brevo Sendinblue for WooCommerce woocommerce-sendinblue-newsletter-subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendinblue for WooCommerce: from n/a through <= 4.0.49. | |
| Analizada | Baja (3.5) | 0.11% | — | Freebox V5 HD FirmwareFreebox V5 Crystal FirmwareFreebox V6 Revolution FirmwareFreebox Mini 4K Firmware+1 | 17/11/2025 | 17/6/2026 | Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over… | |
| Aplazada | Alta (7.5) | 0.37% | — | Fuelthemes RevolutionAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Revolution revolution.This issue affects Revolution: from n/a through < 2.5.8. | |
| Aplazada | Media (6.1) | 0.26% | — | Zucchetti AD HOC RevolutionAI | 30/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahrw/jsp/gsfr_feditorHTML.jsp endpoint. | |
| Aplazada | Alta (8.1) | 0.46% | — | Themesion GrevoAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This issue affects Grevo: from n/a through <= 2.4. | |
| Aplazada | Media (6.5) | 0.38% | — | Themepunch Slider RevolutionAI | 9/10/2025 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with Contributor-level access and above, to install and… | |
| Aplazada | Media (6.5) | 0.53% | — | Themepunch Slider RevolutionAI | 29/8/2025 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server,… | |
| Aplazada | Alta (7.1) | 0.24% | — | Lambertgroup Revolution Video Player With Bottom PlaylistAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player With Bottom Playlist revolution-video-player allows Reflected XSS.This issue affects Revolution Video Player With Bottom Playlist: from n/a through <= 2.9.2. | |
| Analizada | Media (6.4) | 0.17% | — | Mechrevo Control Center GX V2 | 15/8/2025 | 17/6/2026 | A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命控制中心\AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to uncontrolled search path. Local access is required to approach… | |
| Analizada | Media (6.4) | 0.17% | — | Mechrevo Control Center GX V2 | 15/8/2025 | 17/6/2026 | A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The… | |
| Analizada | Alta (7.5) | 0.53% | — | Coderevolution Aiomatic | 24/6/2025 | 17/6/2026 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all versions up to, and including, 2.5.0. This makes it possible for… |