Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.30% | — | AutomatorcwpAI | 24/8/2026 | 26/8/2026 | Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. | |
| Aplazada | Media (4.3) | 0.40% | — | AutomatorwpAI | 22/8/2026 | 24/8/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (4.3) | 0.44% | — | AutomatorwpAI | 22/8/2026 | 24/8/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (7.3) | 3.2% | — | Ucdok TomatoAI | 6/8/2026 | 12/8/2026 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Alta (7.3) | 3.2% | — | Ucdok TomatoAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Alta (7.3) | 3.2% | — | Ucdok TomatoAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly… | |
| Aplazada | Alta (7.5) | 0.73% | — | Uncannyowl Uncanny AutomatorAI | 28/7/2026 | 28/7/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and… | |
| Aplazada | Alta (7.6) | 0.38% | — | Uncannyowl Uncanny AutomatorAI | 23/7/2026 | 23/7/2026 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | |
| Aplazada | Alta (8.7) | 0.79% | — | Ucdok TomatoAI | 18/7/2026 | 20/7/2026 | A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. | |
| Aplazada | Alta (8.7) | 0.79% | — | Ucdok TomatoAI | 18/7/2026 | 22/7/2026 | A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato. | |
| Aplazada | Alta (8.7) | 0.73% | — | Ucdok TomatoAI | 18/7/2026 | 20/7/2026 | A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato. | |
| Aplazada | Alta (8.1) | 1.0% | — | Uncannyowl Uncanny AutomatorAI | 16/7/2026 | 17/7/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.4) | 0.79% | — | FreshtomatoAIUcdok TomatoAI | 13/7/2026 | 15/7/2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This project is… | |
| Aplazada | Baja (2.1) | 1.8% | — | FreshtomatoAIUcdok TomatoAI | 13/7/2026 | 13/7/2026 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 1.8% | — | Ucdok TomatoAI | 13/7/2026 | 13/7/2026 | A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing a manipulation of the argument jffs2_exec results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the… | |
| Aplazada | Alta (7.4) | 0.73% | — | Ucdok TomatoAI | 13/7/2026 | 13/7/2026 | A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Alta (7.4) | 0.79% | — | Ucdok TomatoAI | 13/7/2026 | 13/7/2026 | A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Uncanny Automator PROAI | 7/7/2026 | 7/7/2026 | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Uncanny Automator PROAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | Uncannyowl Uncanny AutomatorAI | 26/6/2026 | 26/6/2026 | Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | AutomatorwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions. | |
| Aplazada | Alta (7.2) | 0.28% | — | AutomatorwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. | |
| Aplazada | Alta (7.3) | 2.7% | — | Ucdok TomatoAI | 4/6/2026 | 22/7/2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is… | |
| Aplazada | Alta (7.3) | 2.6% | — | Ucdok TomatoAI | 4/6/2026 | 22/7/2026 | A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. This project is… | |
| Aplazada | Alta (7.3) | 2.2% | — | Ucdok TomatoAI | 4/6/2026 | 22/7/2026 | A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The exploit has been… |