Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.34% | — | Topoteretes CogneeAI | 4/10/2026 | 4/10/2026 | A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in… | |
| Aplazada | Alta (7.1) | 0.45% | — | HashtopolisAI | 17/7/2026 | 17/7/2026 | Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance. | |
| Aplazada | Alta (7.1) | 0.26% | — | Lemonadestudio Lemonade Social Networks Autoposter PinterestAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0. | |
| Aplazada | Crítica (9.8) | 0.90% | — | Xpodas OctopodAI | 21/3/2024 | 17/6/2026 | Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affects Octopod: before v1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Modificada | Alta (7.5) | 1.2% | — | Autopolis Bulgarisation FOR Woocommerce | 13/3/2024 | 17/6/2026 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and… | |
| Modificada | Media (4.3) | 0.18% | — | Autopolis Bulgarisation FOR Woocommerce | 12/3/2024 | 17/6/2026 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged… | |
| Modificada | Media (5.5) | 0.25% | — | NI Topografix Data PluginNI DiademNI VeristandNI Flexlogger | 8/11/2023 | 17/6/2026 | An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file. | |
| Modificada | Baja (3.3) | 0.21% | — | Octopoller Project Octopoller | 15/6/2022 | 17/6/2026 | Octopoller is a micro gem for polling and retrying. Version 0.2.0 of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Crítica (9.8) | 2.0% | — | Mlmsoftwarez ADD Clicking MLM SoftwareMlmsoftwarez Autopool MLM SoftwareMlmsoftwarez Bidding MLM SoftwareMlmsoftwarez Binary MLM Software+6 | 24/5/2019 | 17/6/2026 | SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the… | |
| Modificada | Alta (7.5) | 1.1% | — | Megacryptopolis | 6/8/2018 | 17/6/2026 | The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not… | |
| Modificada | Media (6.1) | 0.80% | — | Hashtopolis | 27/7/2017 | 17/6/2026 | Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) version, (2) url, or (3) rootdir parameter in hashcat.php. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Virtual Topology System | 24/11/2015 | 17/6/2026 | Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379. | |
| Modificada | Media (6.5) | 3.3% | — | Photopost Vbgallery | 26/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in a certain path. NOTE: this may be the same… | |
| Modificada | Alta (7.5) | 2.1% | — | Don3 Desktoponnet | 10/6/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_path parameter to (1) don3_requiem.don3app/don3_requiem.php and (2) frontpage.don3app/frontpage.php. | |
| Modificada | Alta (10) | 3.5% | — | Photopost Vbgallery | 12/1/2008 | 16/6/2026 | Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 4.2% | — | Photopost PHP PRO | 26/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-admlog.php, (3) adm-approve.php, (4) adm-backup.php, (5) adm-cats.php, (6) adm-cinc.php, (7) adm-db.php, (8) adm-editcfg.php, (9)… | |
| Modificada | Alta (7.5) | 6.5% | — | Photopost PHP PRO | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter. | |
| Modificada | Media (5) | 1.4% | — | EJ3 Topo | 25/7/2006 | 16/6/2026 | index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite existing entries and establish new passwords for the overwritten entries via a URL with a modified entry ID. | |
| Modificada | Media (5) | 0.99% | — | EJ3 Topo | 25/7/2006 | 16/6/2026 | EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | EJ3 Topo | 12/7/2006 | 16/6/2026 | Direct static code injection vulnerability in code/class_db_text.php in EJ3 TOPo 2.2.178 and earlier allows remote attackers to execute arbitrary PHP code via parameters such as (1) descripcion and (2) pais, which are stored directly in a PHP script. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (4.3) | 2.0% | — | EJ3 Topo | 3/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the gTopNombre parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Photopost PHP PRO | 30/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | |
| Modificada | Media (4.3) | 2.0% | — | EJ3 Topo | 24/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section. | |
| Modificada | Media (5) | 1.5% | — | EJ3 Topo | 24/5/2005 | 16/6/2026 | TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses. |