Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
1207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 4/8/2026 | 26/8/2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Softmarket Digital MarketplaceAI | 3/8/2026 | 26/8/2026 | The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Alta (7.2) | 1.2% | — | Easydigitaldownloads Easy Digital DownloadsAI | 29/7/2026 | 30/7/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header… | |
| Aplazada | Media (6.1) | 0.25% | — | Thewp Digital Solutions News ThemeAI | 28/7/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026. | |
| Aplazada | Media (4.9) | 0.50% | — | Easydigitaldownloads Easy Digital DownloadsAI | 27/7/2026 | 27/7/2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | |
| Aplazada | Media (6.5) | 0.47% | — | Premium Packages Sell Digital Products SecurelyAI | 23/7/2026 | 23/7/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (6.4) | 0.42% | — | Equalize Digital Accessibility CheckerAI | 23/7/2026 | 23/7/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.7) | 0.40% | — | Digital-peak DP CalendarAIJoomlaAI | 15/7/2026 | 23/7/2026 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Openasset Digital Asset ManagementAI | 14/7/2026 | 15/7/2026 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function | |
| Aplazada | Baja (2) | 0.43% | — | Pretix-digitalAI | 25/6/2026 | 25/6/2026 | Malicious HTML content could be injected into the content rendered by the pretix-digital plugin. | |
| Aplazada | Media (4.3) | 0.40% | — | Equalize Digital Accessibility CheckerAI | 18/6/2026 | 18/6/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.35% | — | Easydigitaldownloads Easy Digital DownloadsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. | |
| Aplazada | Alta (8.4) | 0.13% | — | Slate Digital ConnectAI | 10/6/2026 | 17/6/2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve… | |
| Aplazada | Alta (8.4) | 0.12% | — | Slate Digital ConnectAI | 10/6/2026 | 17/6/2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing… | |
| Analizada | Alta (8.7) | 0.92% | — | Hcltech Digital ExperienceHcltech Digital Experience Compose | 5/6/2026 | 23/7/2026 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise. | |
| Analizada | Media (6.1) | 0.14% | — | Hcltech Digital Experience ComposeHcltech Digital Experience | 5/6/2026 | 23/7/2026 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways. | |
| Analizada | Media (6.1) | 0.15% | — | Hcltech Digital Experience ComposeHcltech Digital Experience | 5/6/2026 | 23/7/2026 | HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser. | |
| Aplazada | Alta (8.8) | 0.41% | — | Roche Diagnostics Navify Digital PathologyAIRabbitmqAI | 2/6/2026 | 22/7/2026 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1. | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Media (4.3) | 0.47% | — | Equalize Digital Accessibility CheckerAI | 28/5/2026 | 17/6/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.20% | — | Easydigitaldownloads Easy Digital DownloadsAI | 28/5/2026 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a… |