Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.44%—OptincraftAI6/6/202623/7/2026
The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
Pendiente de análisisMedia (5.3)0.40%—Wikimedia MediawikiAIWikimedia ReportincidentAI7/4/202621/7/2026
Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.
AplazadaAlta (7.1)0.23%—Wpinstinct Woo-vehicle-parts-finderAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
AplazadaCrítica (9.8)0.50%—Wpinstinct WOO Vehicle Parts FinderAI22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
AplazadaMedia (5.8)0.72%—Pitinca XlsxviewerAI22/1/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.This issue affects XLSXviewer: from n/a through <= 2.1.1.
AnalizadaAlta (7.5)0.56%—Opigno Tincan Question Type9/1/202517/6/2026
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.
AplazadaCrítica (9.1)30%—Distinct Intranet ServersAI21/6/202416/6/2026
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands.
AplazadaAlta (7.3)0.41%—Instinct UI WEB ClientAI2/4/202417/6/2026
A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.
ModificadaMedia (6.5)1.2%—Khronos OpenclKhronos VulkanImaginationtech DDKAMD Instinct Mi300x Firmware+12816/1/202417/6/2026
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
ModificadaAlta (8.8)0.80%—Narolainfotech Export Users Data Distinct7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.
ModificadaCrítica (9.8)1.2%—Bestsoftinc Online Hotel Booking System30/6/202217/6/2026
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.91%—Bestsoftinc Online Hotel Booking System30/6/202217/6/2026
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)1.2%—Bestsoftinc CAR Rental System5/7/202017/6/2026
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
ModificadaMedia (5.9)0.95%—Tinc-vpn TincDebian LinuxStarwindsoftware Starwind Virtual SAN10/10/201817/6/2026
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
ModificadaBaja (3.7)1.4%—Tinc-vpn TincDebian LinuxStarwindsoftware Starwind Virtual SAN10/10/201817/6/2026
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
ModificadaMedia (5.3)1.5%—Tinc-vpn TincStarwindsoftware Starwind Virtual SAN10/10/201817/6/2026
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
ModificadaAlta (7.5)0.99%—Distinctdev THE Moron Test15/8/201817/6/2026
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
ModificadaMedia (4.3)3.3%—Bestsoftinc Advance Hotel Booking System11/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
ModificadaMedia (6.5)61%—Tinc-vpn Tinc26/4/201316/6/2026
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.
ModificadaMedia (4.3)1.6%—Tincan Phplist1/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.99%—Bestsoftinc Advance Hotel Booking System8/7/201116/6/2026
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaMedia (4.3)0.76%—Tincan Phplist13/4/201116/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748.…
ModificadaMedia (6.8)1.5%—Tincan Phplist13/4/201116/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts.
ModificadaMedia (5)0.89%—Dustincowell Free Simple Software26/11/201016/6/2026
Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.
ModificadaAlta (7.5)0.97%—Dustincowell Free Simple Software26/11/201016/6/2026
SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php.