Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
2294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | — | — | Visitors Traffic Real Time Statistics PROAI | 2/10/2026 | 2/10/2026 | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers… | |
| Pendiente de análisis | Crítica (9.8) | 0.17% | — | Wikimedia EasytimelineAI | 29/9/2026 | 1/10/2026 | XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Altumcode 66uptimeAIAltumcode 66uptime Ping ServersAI | 29/9/2026 | 29/9/2026 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | HCL SametimeAI | 24/9/2026 | 24/9/2026 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without sufficient sanitization, malicious actors can leverage this vulnerability. | |
| Aplazada | Alta (7.6) | 0.29% | — | UltimeterAI | 23/9/2026 | 23/9/2026 | Editor SQL Injection in Ultimeter <= 3.0.8 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Product Badge Label Countdown Timer FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products. | |
| Aplazada | Media (6.5) | 0.45% | — | Supabase RealtimeAI | 21/9/2026 | 24/9/2026 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that… | |
| Aplazada | Baja (1.9) | 0.35% | — | LeantimeAI | 21/9/2026 | 21/9/2026 | A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has… | |
| Aplazada | Baja (2) | 0.36% | — | LeantimeAI | 21/9/2026 | 21/9/2026 | A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Openpanel Js-runtimeAI | 19/9/2026 | 22/9/2026 | OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function… | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | |
| Aplazada | Alta (7.1) | 0.53% | — | LeantimeAI | 16/9/2026 | 17/9/2026 | Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins. | |
| Pendiente de análisis | Crítica (9.5) | 0.69% | — | Arista EOSAIP4runtimeAI | 16/9/2026 | 17/9/2026 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the… | |
| Aplazada | Alta (8.5) | 3.4% | — | Iptime C200eAI | 15/9/2026 | 15/9/2026 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Alta (7.5) | 0.60% | — | Xiongmai Xm530AIXiongmai Sofia IPCAIXiongmai Happytime Rtsp ServerAI | 11/9/2026 | 22/9/2026 | An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over… | |
| Aplazada | Media (6.4) | 0.36% | — | Bold-themes Bold Timeline LiteAI | 11/9/2026 | 11/9/2026 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (8.1) | 0.50% | — | Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 7/9/2026 | 8/9/2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 11/9/2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 9/9/2026 | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Class AND Exam Timetabling SystemAI | 6/9/2026 | 8/9/2026 | A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be… |