Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.44% | — | OptincraftAI | 6/6/2026 | 23/7/2026 | The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Wikimedia MediawikiAIWikimedia ReportincidentAI | 7/4/2026 | 21/7/2026 | Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch. | |
| Aplazada | Alta (7.1) | 0.23% | — | Wpinstinct Woo-vehicle-parts-finderAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpinstinct WOO Vehicle Parts FinderAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. | |
| Aplazada | Media (5.8) | 0.72% | — | Pitinca XlsxviewerAI | 22/1/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-viewer allows Path Traversal.This issue affects XLSXviewer: from n/a through <= 2.1.1. | |
| Analizada | Alta (7.5) | 0.56% | — | Opigno Tincan Question Type | 9/1/2025 | 17/6/2026 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3. | |
| Aplazada | Crítica (9.1) | 30% | — | Distinct Intranet ServersAI | 21/6/2024 | 16/6/2026 | Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands. | |
| Aplazada | Alta (7.3) | 0.41% | — | Instinct UI WEB ClientAI | 2/4/2024 | 17/6/2026 | A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL. | |
| Modificada | Media (6.5) | 1.2% | — | Khronos OpenclKhronos VulkanImaginationtech DDKAMD Instinct Mi300x Firmware+128 | 16/1/2024 | 17/6/2026 | A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures. | |
| Modificada | Alta (8.8) | 0.80% | — | Narolainfotech Export Users Data Distinct | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3. | |
| Modificada | Crítica (9.8) | 1.2% | — | Bestsoftinc Online Hotel Booking System | 30/6/2022 | 17/6/2026 | A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.91% | — | Bestsoftinc Online Hotel Booking System | 30/6/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 1.2% | — | Bestsoftinc CAR Rental System | 5/7/2020 | 17/6/2026 | An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields. | |
| Modificada | Media (5.9) | 0.95% | — | Tinc-vpn TincDebian LinuxStarwindsoftware Starwind Virtual SAN | 10/10/2018 | 17/6/2026 | Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. | |
| Modificada | Baja (3.7) | 1.4% | — | Tinc-vpn TincDebian LinuxStarwindsoftware Starwind Virtual SAN | 10/10/2018 | 17/6/2026 | tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1. | |
| Modificada | Media (5.3) | 1.5% | — | Tinc-vpn TincStarwindsoftware Starwind Virtual SAN | 10/10/2018 | 17/6/2026 | tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation. | |
| Modificada | Alta (7.5) | 0.99% | — | Distinctdev THE Moron Test | 15/8/2018 | 17/6/2026 | DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. | |
| Modificada | Media (4.3) | 3.3% | — | Bestsoftinc Advance Hotel Booking System | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (6.5) | 61% | — | Tinc-vpn Tinc | 26/4/2013 | 16/6/2026 | Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet. | |
| Modificada | Media (4.3) | 1.6% | — | Tincan Phplist | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.99% | — | Bestsoftinc Advance Hotel Booking System | 8/7/2011 | 16/6/2026 | SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 0.76% | — | Tincan Phplist | 13/4/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748.… | |
| Modificada | Media (6.8) | 1.5% | — | Tincan Phplist | 13/4/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts. | |
| Modificada | Media (5) | 0.89% | — | Dustincowell Free Simple Software | 26/11/2010 | 16/6/2026 | Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 0.97% | — | Dustincowell Free Simple Software | 26/11/2010 | 16/6/2026 | SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php. |