Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.2% | — | Bitintegrations BIT IntegrationsAI | 1/8/2026 | 12/8/2026 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary… | |
| Aplazada | Baja (2.1) | 0.51% | — | Investintech SlimpdfreaderAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate… | |
| Aplazada | Baja (2.1) | 0.43% | — | Investintech SlimpdfereaderAI | 17/5/2026 | 17/6/2026 | A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The… | |
| Aplazada | Alta (8.1) | 0.53% | — | Themerex TintAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tint tint allows PHP Local File Inclusion.This issue affects Tint: from n/a through <= 1.7. | |
| Aplazada | Media (6.5) | 0.17% | — | Justintadlock SeriesAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Series series allows Stored XSS.This issue affects Series: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Justintadlock Query PostsAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Query Posts query-posts allows Stored XSS.This issue affects Query Posts: from n/a through <= 0.3.2. | |
| Analizada | Media (6.1) | 0.18% | — | Justintadlock Javascript-logic | 15/5/2025 | 17/6/2026 | The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Media (4.3) | 0.18% | — | Justintadlock Widgets Reset | 15/5/2025 | 17/6/2026 | The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.48% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.33% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.29% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (5.4) | 0.26% | — | Martintod Rotating Tweets | 6/6/2024 | 17/6/2026 | The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's' 'rotatingtweets' in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.41% | — | Justintadlock UniqueAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0. | |
| Modificada | Media (5.4) | 0.57% | — | Rushstreetinteractive Rushbet | 18/1/2023 | 17/6/2026 | RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Rootinteractive | 24/6/2022 | 17/6/2026 | The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Alta (7.8) | 2.0% | — | Investintech Able2extract | 5/11/2019 | 17/6/2026 | An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a… | |
| Modificada | Alta (7.8) | 2.0% | — | Investintech Able2extract | 5/11/2019 | 17/6/2026 | An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially… | |
| Modificada | Alta (8.8) | 2.2% | — | Ynetinteractive Mobiketa | 9/5/2019 | 17/6/2026 | Ynet Interactive - http://demo.ynetinteractive.com/mobiketa/ Mobiketa 4.0 is affected by: SQL Injection. The impact is: Code execution (remote). | |
| Modificada | Crítica (9.8) | 3.6% | — | Ynetinteractive SOA School Management | 9/5/2019 | 17/6/2026 | Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote). | |
| Modificada | Crítica (9.8) | 5.2% | — | Tintin++ Project Tintin++Tintin++ Project Wintin++ | 18/2/2019 | 17/6/2026 | Stack-based buffer overflow in the strip_vt102_codes function in TinTin++ 2.01.6 and WinTin++ 2.01.6 allows remote attackers to execute arbitrary code by sending a long message to the client. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Absolute PDF Server | 1/11/2011 | 16/6/2026 | Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 7.5% | — | Investintech Able2extractInvestintech Able2extract Server | 1/11/2011 | 16/6/2026 | Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document. | |
| Modificada | Alta (9.3) | 7.5% | — | Investintech Able2doc | 1/11/2011 | 16/6/2026 | Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document. | |
| Modificada | Alta (9.3) | 7.4% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. |