Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.29%—Teconceptheme Electio CoreAI20/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows Blind SQL Injection.This issue affects Electio Core: from n/a through <= 1.4.
AplazadaCrítica (9.3)0.43%—Teconceptheme Coven CoreAI20/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through <= 1.3.
AplazadaAlta (7.2)0.20%—Teconceptheme AllmartAI4/7/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery.This issue affects Allmart: from n/a through <= 1.0.0.
AplazadaAlta (7.1)0.27%—Blaze Concepts Better Customer List FOR WoocommerceAI16/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Better Customer List for WooCommerce woo-better-customer-list allows Reflected XSS.This issue affects Better Customer List for WooCommerce: from n/a through <= 1.2.3.
AplazadaMedia (6.5)0.32%—Kugou Technology CO LTD Kugou Concept IOSAI27/1/202517/6/2026
An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via supplying a crafted link.
ModificadaCrítica (9.8)0.48%—Conceptintermedia S@M CMS28/6/202417/6/2026
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
ModificadaMedia (6.1)0.33%—Conceptintermedia S@M CMS28/6/202417/6/2026
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
ModificadaMedia (6.1)0.29%—Conceptintermedia S@M CMS28/6/202417/6/2026
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
AplazadaAlta (7.5)0.42%—CPF Concepts LLC BizprintAI9/6/202417/6/2026
Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39.
AplazadaAlta (7.1)0.19%—CPF Concepts LLC BizprintAI27/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects BizPrint: from n/a through 4.5.5.
ModificadaCrítica (9.8)0.52%—Dmconcept Configurator19/10/202317/6/2026
DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken.
ModificadaAlta (7.2)0.96%—Conceptbeans Mapwiz13/2/202317/6/2026
The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
ModificadaAlta (8.8)0.68%—Summitmediaconcepts Ucontext FOR Clickbank6/9/202217/6/2026
The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for…
ModificadaAlta (8.8)0.76%—Summitmediaconcepts Ucontext FOR Amazon6/9/202217/6/2026
The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for…
ModificadaMedia (6.1)0.81%—Kandnconcepts Club CMS Project Kandnconcepts Club CMS27/8/202017/6/2026
KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
ModificadaCrítica (9.8)1.6%—Kandnconcepts Club CMS Project Kandnconcepts Club CMS27/8/202017/6/2026
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
ModificadaAlta (8.8)0.56%—Conceptronic Cipcamptiwl FirmwareConceptronic Cipcamptiwl WEB Firmware30/1/201817/6/2026
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account.
ModificadaAlta (7.5)32%—Conceptronic Cipcamptiwl FirmwareConceptronic Cipcamptiwl WEB Firmware30/1/201817/6/2026
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device.
ModificadaAlta (9.3)22%—Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+91/4/201416/6/2026
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.
ModificadaMedia (6.8)11%—Conceptronic Cipcamptiwl 1.0 FirmwareConceptronic Cipcamptiwl17/1/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users.
ModificadaAlta (7.8)1.5%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as demonstrated by stored XSS attacks.
ModificadaMedia (4.3)1.2%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to goform/formWlanSetup.
ModificadaMedia (4.3)0.98%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action.
ModificadaMedia (5.8)1.2%—Conceptronic C54apm FirmwareConceptronic C54apm10/1/201417/6/2026
Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the submit-url parameter in a Refresh action to goform/formWlSiteSurvey or (2) the wlan-url parameter to…
ModificadaMedia (5)1.4%—Conceptcms23/9/201116/6/2026
conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files.