Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 299 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.11%—Imprivata EAMAI23/9/202625/9/2026
Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.
AplazadaCrítica (9.8)0.50%—Private Feed KEYAI17/9/202618/9/2026
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
AplazadaAlta (7.1)0.25%—Gallery Private Photo VaultAI14/9/202618/9/2026
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
AplazadaBaja (3.7)0.28%—Zatzlabs MY Private SiteAI5/9/20268/9/2026
The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.
AplazadaCrítica (10)0.52%—WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI31/8/20261/9/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
AplazadaNinguna (0)0.54%—PrivatebinAI28/8/20269/9/2026
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation marks, angle brackets, or apostrophes, and Controller::_init() stores the…
AplazadaMedia (4.3)0.37%—PrivatebinAI28/8/20269/9/2026
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobUrl to create a same-origin blob before setting attachmentLink's href for the…
AplazadaMedia (6.5)0.25%—Privacy Policy Generator Terms ConditionsAI26/8/202626/8/2026
The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected service's API secret and account…
AplazadaMedia (5.3)0.26%—Myagileprivacy MY Agile PrivacyAI25/8/202628/9/2026
The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.3)0.25%—Private-ipAIAxiosAI20/8/202624/9/2026
The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and…
Pendiente de análisisAlta (8.4)0.53%—Rockwellautomation Factorytalk Datamosaix Private CloudAI14/7/202614/7/2026
A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on…
AplazadaCrítica (9.8)0.53%—Lcweb PrivatecontentAI1/7/20261/7/2026
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.
AplazadaAlta (7.1)0.41%—Epiph Embed PrivacyAI29/6/202629/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
AplazadaMedia (6.4)0.23%—File Sharing Download Manager User Private FilesAI16/6/202617/6/2026
The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.27%—Apple Private Cloud Compute18/5/202630/6/2026
An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.
AplazadaAlta (8.5)0.12%—Privacy DriveAI16/5/202617/6/2026
Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with LocalSystem…
AplazadaMedia (4.4)0.30%—Private WP SuiteAI22/4/202617/6/2026
The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in all versions up to, and including, 0.4.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and…
AplazadaMedia (6.4)0.36%—Lcweb PrivatecontentAI8/4/202624/7/2026
The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attribute in the [pc-login-form] shortcode in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on the 'align' attribute. Specifically, the…
AnalizadaCrítica (9.6)0.32%—HPE Aruba Networking Private 5G Core7/4/202617/6/2026
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled…
AnalizadaAlta (8.4)0.22%—Tinybeans Private Family Album1/4/202617/6/2026
An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AplazadaMedia (4.4)0.25%—Private CommentAI18/2/202617/6/2026
The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is due to insufficient input sanitization and output escaping on the plugin's label text option. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.34%—HPE Aruba Networking Private 5G Core17/2/202617/6/2026
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight…
AnalizadaMedia (6.5)0.26%—HPE Aruba Networking Private 5G Core17/2/202617/6/2026
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight…
AnalizadaMedia (6.5)0.25%—HPE Aruba Networking Private 5G Core17/2/202617/6/2026
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.
AnalizadaAlta (8.8)0.31%—HPE Aruba Networking Private 5G Core17/2/202617/6/2026
An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or…