Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.29% | — | Yii2 Starter KITAI | 30/9/2026 | 1/10/2026 | yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Yii2 Starter KIT Yii2-starter-kitAI | 30/9/2026 | 30/9/2026 | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii… | |
| Aplazada | Alta (8.7) | 0.39% | — | Yii2 Starter KITAI | 30/9/2026 | 30/9/2026 | yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server. | |
| Aplazada | Media (4.3) | 0.25% | — | Starter TemplatesAI | 11/9/2026 | 11/9/2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | |
| Aplazada | Baja (1.3) | 0.31% | — | Lognet Grpc-spring-boot-starterAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability… | |
| Aplazada | Alta (7.5) | 0.46% | — | Kadencewp Starter TemplatesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | |
| Aplazada | Baja (2.3) | 0.32% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack… | |
| Aplazada | Media (5.3) | 0.34% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.36% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely. | |
| Analizada | Media (5.8) | 0.42% | — | Amazon Bedrock Agentcore Starter Toolkit | 16/3/2026 | 17/6/2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Katana Network Development Starter KITAI | 23/1/2026 | 17/6/2026 | Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Katana Network Development Starter Kit. Authentication is not required to exploit this vulnerability. The… | |
| Modificada | Crítica (9.8) | 40% | — | Advantech IOT Edge Linux DockerAdvantech IOT Edge WindowsAdvantech Iotsuite Growth Linux DockerAdvantech Iotsuite Saas Composer+1 | 12/1/2026 | 17/6/2026 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administrators of affected product… | |
| Aplazada | Alta (8.8) | 14% | — | Starter TemplatesAI | 6/12/2025 | 17/6/2026 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Aplazada | Media (5.4) | 0.19% | — | SAP Starter SolutionAI | 11/11/2025 | 17/6/2026 | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low impact on the application's confidentiality and integrity but no impact on its availability. | |
| Aplazada | Alta (8.5) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+5 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC… | |
| Aplazada | Media (6.8) | 0.17% | — | Siemens Simotion Scout TIAAISiemens Simotion ScoutAISiemens Sinamics StarterAI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT V5.5 (All versions), SIMOTION SCOUT… | |
| Aplazada | Alta (8.6) | 0.17% | — | Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All… | |
| Aplazada | Media (6.1) | 0.30% | — | Laravel StarterAI | 22/4/2025 | 17/6/2026 | Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field. | |
| Aplazada | Media (5.9) | 0.35% | — | Hackathon-starterAI | 1/4/2025 | 17/6/2026 | An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component. | |
| Analizada | Crítica (9.1) | 0.43% | — | Fancywp Starter Templates | 8/3/2025 | 17/6/2026 | The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web… | |
| Aplazada | Alta (8.7) | 0.56% | — | Siemens Simatic PCS NEOAISiemens Simocode ESAISiemens Sirius Safety ESAISiemens Sirius Soft Starter ESAI+1 | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES… | |
| Aplazada | Crítica (9.6) | 0.24% | — | Fancywp Starter TemplatesAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross Site Request Forgery.This issue affects Starter Templates by FancyWP: from n/a through <= 2.0.0. | |
| Aplazada | Alta (7) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic Step 7 SafetyAISiemens Simatic WinccAI+8 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4), SIMATIC STEP 7 V17 (All versions < V17 Update… | |
| Aplazada | Alta (8.4) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),… | |
| Aplazada | Alta (7) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP… |