Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.40% | — | LubeloggerAI | 18/9/2026 | 30/9/2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming destination vehicleIds the user could edit. The endpoint authorized the… | |
| Aplazada | Alta (8.1) | 0.51% | — | LubeloggerAI | 18/9/2026 | 24/9/2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controllers/FilesController.cs to RenameFile in Helper/FileHelper.cs. RenameFile… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Faydam Innovation INC Faydam DataloggerAI | 19/8/2026 | 26/8/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Sfcyazilim SonloggerAI | 17/8/2026 | 26/8/2026 | Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8. | |
| Aplazada | Alta (7.5) | 0.39% | — | FortiloggerAI | 17/8/2026 | 26/8/2026 | Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9. | |
| Aplazada | Alta (8.8) | 0.55% | — | Tbea TloggerAI | 10/8/2026 | 29/9/2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application data, or terminate the web server through a segmentation fault. In addition,… | |
| Aplazada | Alta (8.7) | 0.54% | — | Tbea TloggerAI | 10/8/2026 | 29/9/2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing the web server to create persistent files containing attacker-controlled data under /opt/myapp/webserver/. The generated… | |
| Aplazada | Crítica (9.2) | 0.68% | — | Tbea TloggerAI | 10/8/2026 | 29/9/2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access… | |
| Aplazada | Baja (2.4) | 0.21% | — | Tbea TloggerAI | 10/8/2026 | 29/9/2026 | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Tbea TloggerAI | 10/8/2026 | 29/9/2026 | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Tbea TloggerAI | 10/8/2026 | 29/9/2026 | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service.… | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Alta (8.8) | 0.35% | — | Spicethemes NewsbloggerAI | 19/2/2026 | 14/9/2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve… | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Logger FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logger for Elementor: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.5) | 0.30% | — | IO FIT AG Life LoggerAI | 30/10/2025 | 17/6/2026 | AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes make brute-force account logins… | |
| Aplazada | Media (5.5) | 0.45% | — | Geyang Ml-loggerAI | 25/9/2025 | 17/6/2026 | A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of the component File Handler. Performing manipulation of the argument key results in information disclosure. The attack can be… | |
| Aplazada | Media (5.5) | 0.61% | — | Geyang Ml-loggerAI | 25/9/2025 | 17/6/2026 | A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vulnerability is the function log_handler of the file ml_logger/server.py. Such manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Baja (2.1) | 0.31% | — | Geyang Ml-loggerAI | 25/9/2025 | 17/6/2026 | A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This manipulation of the argument data causes deserialization. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.6) | 0.80% | — | Developer Loggers FOR Simple HistoryAI | 17/9/2025 | 25/9/2026 | The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the enabled_loggers parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on… | |
| Aplazada | Media (6.5) | 0.21% | — | Sparklewpthemes Blogger BuzzAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Blogger Buzz blogger-buzz allows Stored XSS.This issue affects Blogger Buzz: from n/a through <= 1.2.6. | |
| Aplazada | Media (4.3) | 0.35% | — | Edwardbock Cron LoggerAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in EdwardBock Cron Logger cron-logger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cron Logger: from n/a through <= 1.3.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Yougler Blogger Profile PageAI | 14/6/2025 | 17/6/2026 | The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible for unauthenticated attackers to update the plugin's settings via… | |
| Aplazada | Media (6.3) | 0.41% | — | Sungrow Logger1000AI | 11/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult.… | |
| Analizada | Alta (8.8) | 0.39% | — | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Analizada | Alta (8.8) | 1.1% | — | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… |