Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.40% | — | Convertplug ConvertplusAI | 28/9/2026 | 29/9/2026 | The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the… | |
| Aplazada | Media (5.3) | 0.19% | — | UpdraftplusAI | 27/9/2026 | 28/9/2026 | The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration… | |
| Aplazada | Media (5.9) | 0.14% | — | UpdraftplusAI | 27/8/2026 | 28/8/2026 | The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link. | |
| Aplazada | Baja (1.9) | 0.14% | — | Textplus Text Message AND Call APPAI | 3/8/2026 | 12/8/2026 | A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit is publicly… | |
| Aplazada | Media (5.3) | 0.32% | — | Wpsupportplus WP Support Plus Responsive Ticket SystemAI | 9/7/2026 | 9/7/2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets. | |
| Aplazada | Alta (8.6) | 0.45% | — | Wpsupportplus WP Support Plus Responsive Ticket SystemAI | 30/6/2026 | 30/6/2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Alta (8.8) | 0.51% | — | Wpsupportplus Responsive Ticket SystemAI | 30/6/2026 | 30/6/2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site… | |
| Aplazada | Alta (8.1) | 3.6% | — | UpdraftplusAI | 11/6/2026 | 23/7/2026 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature… | |
| Aplazada | Media (5.4) | 0.38% | — | Updraftplus Wp-optimizeAI | 10/4/2026 | 17/6/2026 | The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking… | |
| Analizada | Crítica (9.8) | 3.8% | — | Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+159 | 20/1/2026 | 17/6/2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. | |
| Modificada | Media (5.1) | 0.22% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a… | |
| Analizada | Alta (8.7) | 0.78% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting… | |
| Analizada | Crítica (9.3) | 0.39% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations. | |
| Modificada | Alta (7.1) | 0.49% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring… | |
| Analizada | Alta (7.1) | 0.47% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and… | |
| Modificada | Alta (8.7) | 0.48% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system… | |
| Analizada | Alta (8.7) | 0.60% | — | Microhardcorp Ipn4g FirmwareMicrohardcorp Ipn3gb FirmwareMicrohardcorp Ipn4gb FirmwareMicrohardcorp Bullet-3g Firmware+7 | 24/12/2025 | 17/6/2026 | Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges. | |
| Aplazada | Media (5.5) | 0.30% | — | Chanjet TplusAI | 7/12/2025 | 17/6/2026 | A flaw has been found in Chanjet TPlus up to 20251121. Affected by this vulnerability is an unknown functionality of the file /tplus/ajaxpro/Ufida.T.SM.UIP.MultiCompanySettingController,Ufida.T.SM.UIP.ashx?method=Load. This manipulation of the argument currentAccId causes sql injection. It is possible to initiate the… | |
| Analizada | Media (4.1) | 0.32% | — | Updraftplus Wp-optimize | 2/6/2025 | 17/6/2026 | The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Elbisnero WpeventplusAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0. | |
| Analizada | Alta (8.1) | 0.47% | — | Convertplug Convertplus | 12/2/2025 | 17/6/2026 | The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Media (5.1) | 0.29% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/sys/admin.html. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.38% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this vulnerability is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the argument text leads to open redirect.… | |
| Analizada | Media (6.9) | 0.68% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. Affected is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the argument w/h leads to resource consumption. It is possible… | |
| Analizada | Media (5.3) | 0.55% | — | Joeybling Bootplus | 24/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This issue affects some unknown processing of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument name leads to path traversal. The… |