Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.1% | — | Linuxfoundation Spinnaker | 10/7/2026 | 21/7/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing… | |
| Analizada | Alta (8.8) | 1.0% | — | Linuxfoundation Spinnaker | 10/7/2026 | 21/7/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes,… | |
| Aplazada | Alta (8.1) | 0.34% | — | Axiomthemes SpinAIPHPAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This issue affects Spin: from n/a through 1.8. | |
| Analizada | Crítica (9.9) | 0.66% | — | Linuxfoundation Spinnaker | 20/4/2026 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context… | |
| Analizada | Crítica (9.9) | 0.77% | — | Linuxfoundation Spinnaker | 20/4/2026 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1,… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Spinnaker ClouddriverAISpinnaker OrcaAI | 17/3/2026 | 17/6/2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs.… | |
| Analizada | Baja (2) | 0.27% | — | Spin.js | 11/3/2026 | 17/6/2026 | Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution… | |
| Aplazada | Media (6.9) | 0.40% | — | SpinwasmAIContainerd-shim-spinAISpinroot SpinAI | 26/2/2026 | 17/6/2026 | Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to… | |
| Aplazada | Media (5.3) | 0.36% | — | Spin WheelAI | 17/1/2026 | 17/6/2026 | The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or randomization. This makes it possible for unauthenticated attackers to manipulate… | |
| Analizada | Media (6.6) | 0.17% | — | Linuxfoundation Spinnaker | 5/1/2026 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via helm or other… | |
| Analizada | Media (6.9) | 0.40% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error… | |
| Analizada | Alta (8.7) | 0.42% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information. | |
| Analizada | Media (6.9) | 0.27% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges… | |
| Analizada | Alta (8.8) | 0.90% | — | Spinetix Fusion Digital Signage | 10/12/2025 | 17/6/2026 | SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations… | |
| Aplazada | Alta (7.1) | 0.24% | — | Valvepress Wordpress Auto SpinnerAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Reflected XSS.This issue affects Wordpress Auto Spinner: from n/a through <= 3.26.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Sharespine Woocommerce ConnectorAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharespine Woocommerce Connector: from n/a through <= 4.7.55. | |
| Aplazada | Media (4.3) | 0.28% | — | Valvepress WP Auto SpinnerAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wordpress Auto Spinner: from n/a through <= 3.25.0. | |
| Aplazada | Crítica (9.9) | 0.51% | — | Wpspin Post Page Copying ToolAI | 4/2/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Remote Code Inclusion.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.5) | 0.54% | — | Wpspin Post Page Copying ToolAI | 7/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Retrieve Embedded Sensitive Data.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Meini Utech Utech Spinning EarthAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meini Utech Spinning Earth utech-spinning-earth allows DOM-Based XSS.This issue affects Utech Spinning Earth: from n/a through <= 1.2. | |
| Aplazada | Alta (8.3) | 0.34% | — | Upqode Plum Spin Wheel AND Email Pop-upAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. | |
| Aplazada | Media (5.3) | 0.40% | — | Upqode Plum Spin Wheel AND Email Pop-upAI | 1/11/2024 | 17/6/2026 | Access Control vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows . This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. | |
| Modificada | Media (6.9) | 0.43% | — | Denkgroot Spina | 25/7/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (6.9) | 0.36% | — | Denkgroot Spina | 24/7/2024 | 17/6/2026 | A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown function of the file /admin/pages/. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Crítica (9.6) | 0.21% | — | Denkgroot Spina | 19/7/2024 | 17/6/2026 | Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout. |