Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 557 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Hostinger MigratorAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Pencidesign Penci Soledad Data MigratorAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Soledad Data Migrator penci-data-migrator allows Reflected XSS.This issue affects Penci Soledad Data Migrator: from n/a through <= 1.3.1. | |
| Aplazada | Crítica (9.6) | 0.21% | — | GMO Wing Wing Wordpress MigratorAI | 30/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This issue affects WING WordPress Migrator: from n/a through <= 1.2.0. | |
| Analizada | Alta (7.5) | 0.38% | — | Xwiki Confluence Migrator | 7/3/2025 | 17/6/2026 | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7. | |
| Aplazada | Crítica (9.1) | 0.66% | — | Xwiki Confluence Migrator PROAI | 7/3/2025 | 17/6/2026 | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0. | |
| Aplazada | Crítica (9.8) | 0.69% | — | Penci Soledad Data MigratorAI | 17/5/2024 | 17/6/2026 | The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those… | |
| Aplazada | Crítica (9.6) | 0.26% | — | Xserver MigratorAI | 2/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects Xserver Migrator: from n/a through 1.6.1. | |
| Modificada | Crítica (9.8) | 1.3% | — | Surelinesystems Sureedge Migrator | 28/9/2021 | 17/6/2026 | A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360. |