Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.8) | 0.15% | — | IBM Aspera Enterprise WebappsAI | 10/9/2026 | 11/9/2026 | IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container. | |
| Aplazada | Media (6.1) | 0.38% | — | Webappick Product Feed Manager FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Alta (7.2) | 0.85% | — | Webappick CTX FeedAI | 19/2/2026 | 17/6/2026 | The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attackers, with Shop… | |
| Aplazada | Media (5.3) | 0.35% | — | Webappick CTX FeedAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WebAppick CTX Feed webappick-product-feed-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CTX Feed: from n/a through <= 6.6.18. | |
| Aplazada | Media (5.1) | 0.17% | — | Smarthouse WebappAI | 24/12/2025 | 17/6/2026 | SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various… | |
| Analizada | Media (5.5) | 0.10% | — | Wire-webapp | 22/5/2025 | 17/6/2026 | wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the… | |
| Aplazada | Media (5.6) | 0.14% | — | Wire-webappAI | 22/5/2025 | 17/6/2026 | wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again after re-opening the application. This does not happen when the user… | |
| Aplazada | Alta (8.8) | 0.19% | — | Webappick ChallanAIWebappick PDF Invoice FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Challan: from n/a through <= 3.7.58. | |
| Aplazada | Alta (7.5) | 0.37% | — | OPC Cardsystems Webapp AufwertungAI | 26/3/2025 | 17/6/2026 | An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or all transactions with the same reference are completed, depending on timing. This can be used to transfer more money onto employee cards than is paid. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Money Manager EX WebappAI | 24/10/2024 | 17/6/2026 | Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files,… | |
| Aplazada | Alta (7.2) | 0.56% | — | Webappick CTX FeedAI | 1/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6. | |
| Modificada | Media (5.3) | 0.62% | — | Wire-webapp | 27/1/2023 | 17/6/2026 | Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptional Conditions. In the wire-webapp, certain combinations of Markdown formatting can trigger an unhandled error in the conversion to HTML representation. The error makes it impossible to display the… | |
| Modificada | Media (6.1) | 0.52% | — | Webapplication-veganguide Project Webapplication-veganguide | 17/1/2023 | 17/6/2026 | A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the argument country/city leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Media (6.1) | 0.84% | — | Wire-webapp | 25/6/2022 | 17/6/2026 | Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a user receives and views a malicious message, arbitrary code is injected and executed in the context of the victim allowing the attacker to… | |
| Modificada | Media (6.1) | 1.00% | — | Wire-webapp | 20/4/2022 | 17/6/2026 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and views such a malicious message, arbitrary… | |
| Modificada | Baja (2.3) | 0.31% | — | Wire-webapp | 4/2/2022 | 17/6/2026 | Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat history of Wire Webapp. In versions before 2022-01-27-production.0 ephemeral messages and assets might still be accessible through the local… | |
| Modificada | Crítica (9.8) | 3.8% | — | Qxip Homer Webapp | 10/1/2022 | 17/6/2026 | QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations. | |
| Modificada | Media (6.1) | 0.83% | — | Wire-webapp | 15/6/2021 | 17/6/2026 | wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists in wire-webapp prior to version 2021-06-01-production.0. If a user is instructed to open an image in a new tab (right click -> open in new tab, or copy the URL and paste it in the URL bar), an the image… | |
| Modificada | Media (6.5) | 1.1% | — | Wire-webapp | 2/4/2021 | 17/6/2026 | wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typed passphrase will be sent into the most recently used chat when the user does not actively give focus to the input… | |
| Modificada | Media (5.4) | 3.2% | — | Webappick Woocommerce Product Feed | 23/7/2019 | 17/6/2026 | WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in. | |
| Modificada | Crítica (9.8) | 2.8% | — | Saet Tebe Small FirmwareSaet Webapp | 31/5/2019 | 17/6/2026 | The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menu=php://filter/convert.base64-encode/resource=index.php to read index.php. | |
| Modificada | Alta (7.5) | 2.4% | — | Saet Tebe Small FirmwareSaet Webapp | 31/5/2019 | 17/6/2026 | The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call. | |
| Modificada | Crítica (9.8) | 13% | — | Webapp-builder Project Webapp-builder | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ | |
| Modificada | Media (6.1) | 0.75% | — | Kopano Webapp | 26/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file. |