Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 1.1% | — | Adolfosalasgomez3011 Slidev-builder-mcpAI | 8/8/2026 | 12/8/2026 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with… | |
| Aplazada | Alta (7.1) | 0.16% | — | Hamsalam Sync-basalamAI | 13/7/2026 | 13/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1. | |
| Aplazada | Media (4.4) | 0.31% | — | Salavat CounterAI | 19/2/2026 | 17/6/2026 | The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and… | |
| Aplazada | Alta (7.1) | 0.18% | — | Uxper SalaAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3. | |
| Aplazada | Alta (8.1) | 0.44% | — | Uxper SalaAI | 9/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a through 1.1.6. | |
| Aplazada | Alta (7.5) | 0.26% | — | Uxper SalaAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sala: from n/a through 1.1.3. | |
| Aplazada | Crítica (9.8) | 0.62% | — | SalaAI | 9/7/2025 | 17/6/2026 | The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.4. This is due to the theme not properly validating a user's identity prior to updating their details like password. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.41% | — | Uxper SalaAI | 27/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3. | |
| Aplazada | Media (6.4) | 0.34% | — | Muslim Prayer Time Salah IqamahAI | 9/1/2025 | 17/6/2026 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.1) | 0.55% | — | Salavat CounterAI | 21/11/2024 | 17/6/2026 | The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.4) | 0.25% | — | Sercomm Etisalat Model S3 Ac2100AI | 12/11/2024 | 17/6/2026 | Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page. | |
| Aplazada | Alta (7.5) | 0.56% | — | Nahimsalami Ahime Image PrinterAI | 16/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.35% | — | Eftakhairul Islam AND Sirajus Salayhin Easy SET FaviconAI | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eftakhairul Islam & Sirajus Salayhin Easy Set Favicon allows Reflected XSS.This issue affects Easy Set Favicon: from n/a through 1.1. | |
| Modificada | Media (4.8) | 0.53% | — | Salat Times Project Salat Times | 28/11/2022 | 17/6/2026 | The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 1.1% | — | Leyan Salary Management System | 30/8/2022 | 17/6/2026 | Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service. | |
| Modificada | Crítica (9.8) | 0.98% | — | Mesalabs Amegaview | 21/12/2021 | 17/6/2026 | Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application, which may allow an attacker to gain access. | |
| Modificada | Crítica (9.8) | 0.80% | — | Mesalabs Amegaview | 21/12/2021 | 17/6/2026 | Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device. | |
| Modificada | Alta (8.8) | 3.1% | — | Mesalabs Amegaview | 21/12/2021 | 17/6/2026 | Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server. | |
| Modificada | Crítica (9.8) | 2.3% | — | Mesalabs Amegaview | 21/12/2021 | 17/6/2026 | Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.22% | — | Mesalabs Amegaview | 21/12/2021 | 17/6/2026 | Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device. | |
| Modificada | Alta (7.4) | 2.0% | — | Debian LinuxKitfox SVG Salamander | 16/3/2017 | 17/6/2026 | The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file. | |
| Modificada | Baja (2.1) | 1.1% | — | Anibal Monsalve Salaz Ssmtp | 20/8/2010 | 16/6/2026 | The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue because it is solely a usability problem for senders of messages… | |
| Modificada | Media (6.8) | 43% | — | Altap Portable Executable ViewerAltap Servant Salamander | 21/6/2007 | 16/6/2026 | Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file. |