Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.38% | — | Nginx IgnitionAI | 21/9/2026 | 24/9/2026 | nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue. | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Nginx IgnitionAIGolang X TextAI | 21/9/2026 | 24/9/2026 | nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape… | |
| Pendiente de análisis | Alta (8.1) | 0.43% | — | Nginx IgnitionAI | 21/9/2026 | 23/9/2026 | nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Inductiveautomation IgnitionAI | 4/9/2026 | 8/9/2026 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Saleswonder Team Webinar IgnitionAI | 27/5/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Saleswonder Team Webinar IgnitionAI | 27/5/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Saleswonder WebinarignitionAI | 5/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: from n/a through 4.08.253. | |
| Analizada | Media (5.4) | 0.34% | — | Inductiveautomation Ignition | 12/3/2026 | 17/6/2026 | A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code. | |
| Aplazada | Alta (7.3) | 0.25% | — | Inductiveautomation IgnitionAI | 18/12/2025 | 28/8/2026 | Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file… | |
| Aplazada | Media (6.5) | 0.32% | — | Saleswonder Team Webinar-ignitionAI | 18/12/2025 | 30/9/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04. | |
| Aplazada | Media (5.4) | 0.28% | — | Ignitionwp IgnitiondeckAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in ignitionwp IgnitionDeck ignitiondeck allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IgnitionDeck: from n/a through <= 2.0.15. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Saleswonder WebinarignitionAI | 24/7/2025 | 17/6/2026 | The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in_support_staff` and `webinarignition_register_support` functions… | |
| Analizada | Media (6.1) | 0.26% | — | Ignition Error Pages Project Ignition Error Pages | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Error Pages allows Cross-Site Scripting (XSS).This issue affects Ignition Error Pages: from 0.0.0 before 1.0.4. | |
| Aplazada | Media (5.4) | 0.37% | — | Ignitiondeck Crowdfunding PlatformAI | 27/7/2024 | 17/6/2026 | The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability checks on various functions called via AJAX actions in the ~/classes/class-idf-wizard.php file. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.72% | — | Saleswonder WebinarignitionAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0. | |
| Analizada | Alta (8.8) | 2.1% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (8.8) | 1.4% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to… | |
| Analizada | Alta (8.8) | 55% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The… | |
| Analizada | Alta (8.8) | 1.1% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in… | |
| Analizada | Alta (8.8) | 1.1% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this… | |
| Analizada | Alta (8.8) | 1.8% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 1.5% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 55% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition ModuleInvoke Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.5) | 1.5% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Crítica (9.8) | 2.2% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability. The… |