Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.30% | — | RestrictmateAI | 23/8/2026 | 28/8/2026 | The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover. | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Tmate IO TmateAI | 24/3/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Michalzagdan Trustmate IO Integration FOR WoocommerceAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration trustmate-io-integration-for-woocommerce allows Cross Site Request Forgery.This issue affects TrustMate.io – WooCommerce integration: from n/a through <= 1.16.0. | |
| Modificada | Alta (7) | 0.22% | — | Tmate-ssh-server | 7/12/2021 | 17/6/2026 | Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity of session handling. | |
| Modificada | Alta (7) | 0.26% | — | Tmate-ssh-server | 7/12/2021 | 17/6/2026 | World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory. | |
| Modificada | Alta (7.5) | 1.2% | — | Scriptmate User Manager | 15/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via "Manage Resources" and possibly other unspecified components. | |
| Modificada | Alta (7.5) | 1.2% | — | Scriptmate User Manager | 15/12/2006 | 16/6/2026 | SQL injection vulnerability in utilities/usermessages.asp in ScriptMate User Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the mesid parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Scriptmate User Manager | 15/12/2006 | 16/6/2026 | ScriptMate User Manager 2.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors related to (1) the Logins box and (2) the Search box. | |
| Modificada | Media (6.8) | 1.4% | — | Scriptmate User Manager | 15/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) members_username (user) and (2) members_password (password) fields in a login action in members/default.asp, and (3) the Search box. NOTE: some of… |