Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.22% | — | Hmbrand Text\ | 29/4/2026 | 25/6/2026 | Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or on_error) and cache… | |
| Aplazada | Alta (7.5) | 0.63% | 💥 PoC | Aranda Software Aranda Service DeskAI | 28/4/2026 | 17/6/2026 | The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download… | |
| Aplazada | Media (6.4) | 0.32% | — | Simple Random Posts ShortcodeAI | 22/4/2026 | 17/6/2026 | The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the 'simple_random_posts' shortcode in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (5.4) | 0.13% | — | Themegoods Grand MagazineAI | 8/4/2026 | 20/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <= 3.5.5. | |
| Aplazada | Media (5.4) | 0.14% | — | Themegoods Grand PortfolioAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Grand Portfolio: from n/a through <= 3.3. | |
| Aplazada | Media (6.5) | 0.13% | — | Themegoods Grand CAR RentalAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request Forgery.This issue affects Grand Car Rental: from n/a through <= 3.6.9. | |
| Aplazada | Media (6.5) | 0.17% | — | Themegoods Grand BlogAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: from n/a through <= 3.1. | |
| Aplazada | Media (5.4) | 0.14% | — | Themegoods Grand PhotographyAI | 8/4/2026 | 20/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8. | |
| Aplazada | Media (6.4) | 0.33% | — | WP Random ButtonAI | 21/3/2026 | 17/6/2026 | The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the 'wp_random_button' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode… | |
| Aplazada | Alta (8.8) | 0.62% | 💥 PoC | Aranda Service Desk WEB EditionAI | 5/3/2026 | 17/6/2026 | An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, which is processed by… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex LegrandAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Legrand legrand allows PHP Local File Inclusion.This issue affects Legrand: from n/a through <= 2.17. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods Grand NewsAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand News grandnews allows Reflected XSS.This issue affects Grand News: from n/a through <= 3.4.3. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Themegoods Grand WeddingAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through < 3.1.11. | |
| Modificada | Media (5.9) | 0.19% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 3/3/2026 | 17/6/2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20,… | |
| Aplazada | Alta (7.1) | 0.16% | — | Themegoods Grand ConferenceAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference grandconference allows Reflected XSS.This issue affects Grand Conference: from n/a through <= 5.3.4. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Themegoods Grand RestaurantAI | 19/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10. | |
| Analizada | Crítica (9.3) | 41% | 💥 Exploit | Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+2 | 18/2/2026 | 17/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the… | |
| Aplazada | Media (6.4) | 0.24% | — | Orbisius Random Name GeneratorAI | 11/2/2026 | 17/6/2026 | The Orbisius Random Name Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_label' parameter in the 'orbisius_random_name_generator' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.4) | 0.28% | — | Extended Random Number GeneratorAI | 4/2/2026 | 17/6/2026 | The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Media (5.4) | 0.19% | — | Themegoods Grand BlogAI | 3/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods Grand SPAAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Spa grandspa allows Reflected XSS.This issue affects Grand Spa: from n/a through <= 3.5.5. | |
| Aplazada | Alta (7.1) | 0.21% | — | Themegoods Grand MagazineAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Magazine grandmagazine allows Reflected XSS.This issue affects Grand Magazine: from n/a through <= 3.5.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Themegoods Grand TourAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Tour grandtour allows Reflected XSS.This issue affects Grand Tour: from n/a through < 5.6.2. | |
| Aplazada | Media (6.5) | 0.27% | — | Themegoods Grand Restaurant Theme Elements FOR ElementorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1. | |
| Analizada | Alta (7.5) | 0.15% | — | Mrvladus Errands | 12/1/2026 | 17/6/2026 | Errands before 46.2.10 does not verify TLS certificates for CalDAV servers. |