Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 299 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.11% | — | Imprivata EAMAI | 23/9/2026 | 25/9/2026 | Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Private Feed KEYAI | 17/9/2026 | 18/9/2026 | The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators. | |
| Aplazada | Alta (7.1) | 0.25% | — | Gallery Private Photo VaultAI | 14/9/2026 | 18/9/2026 | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage. | |
| Aplazada | Baja (3.7) | 0.28% | — | Zatzlabs MY Private SiteAI | 5/9/2026 | 8/9/2026 | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login. | |
| Aplazada | Crítica (10) | 0.52% | — | WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 31/8/2026 | 1/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1. | |
| Aplazada | Ninguna (0) | 0.54% | — | PrivatebinAI | 28/8/2026 | 9/9/2026 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation marks, angle brackets, or apostrophes, and Controller::_init() stores the… | |
| Aplazada | Media (4.3) | 0.37% | — | PrivatebinAI | 28/8/2026 | 9/9/2026 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobUrl to create a same-origin blob before setting attachmentLink's href for the… | |
| Aplazada | Media (6.5) | 0.25% | — | Privacy Policy Generator Terms ConditionsAI | 26/8/2026 | 26/8/2026 | The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected service's API secret and account… | |
| Aplazada | Media (5.3) | 0.26% | — | Myagileprivacy MY Agile PrivacyAI | 25/8/2026 | 28/9/2026 | The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.25% | — | Private-ipAIAxiosAI | 20/8/2026 | 24/9/2026 | The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and… | |
| Pendiente de análisis | Alta (8.4) | 0.53% | — | Rockwellautomation Factorytalk Datamosaix Private CloudAI | 14/7/2026 | 14/7/2026 | A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Lcweb PrivatecontentAI | 1/7/2026 | 1/7/2026 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2. | |
| Aplazada | Alta (7.1) | 0.41% | — | Epiph Embed PrivacyAI | 29/6/2026 | 29/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3. | |
| Aplazada | Media (6.4) | 0.23% | — | File Sharing Download Manager User Private FilesAI | 16/6/2026 | 17/6/2026 | The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.27% | — | Apple Private Cloud Compute | 18/5/2026 | 30/6/2026 | An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3. | |
| Aplazada | Alta (8.5) | 0.12% | — | Privacy DriveAI | 16/5/2026 | 17/6/2026 | Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with LocalSystem… | |
| Aplazada | Media (4.4) | 0.30% | — | Private WP SuiteAI | 22/4/2026 | 17/6/2026 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in all versions up to, and including, 0.4.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Aplazada | Media (6.4) | 0.36% | — | Lcweb PrivatecontentAI | 8/4/2026 | 24/7/2026 | The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attribute in the [pc-login-form] shortcode in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on the 'align' attribute. Specifically, the… | |
| Analizada | Crítica (9.6) | 0.32% | — | HPE Aruba Networking Private 5G Core | 7/4/2026 | 17/6/2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled… | |
| Analizada | Alta (8.4) | 0.22% | — | Tinybeans Private Family Album | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Media (4.4) | 0.25% | — | Private CommentAI | 18/2/2026 | 17/6/2026 | The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is due to insufficient input sanitization and output escaping on the plugin's label text option. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.34% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.26% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight… | |
| Analizada | Media (6.5) | 0.25% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability. | |
| Analizada | Alta (8.8) | 0.31% | — | HPE Aruba Networking Private 5G Core | 17/2/2026 | 17/6/2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or… |