Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.15% | — | Reachy Mini ISOAI | 30/9/2026 | 30/9/2026 | Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to… | |
| Aplazada | Media (6.8) | 0.24% | — | Hostinger ReachAI | 30/9/2026 | 30/9/2026 | The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content… | |
| Aplazada | Media (6.3) | 0.16% | — | Pollen Robotics Reachy MiniAIBluezAI | 23/9/2026 | 23/9/2026 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride along on someone else's successful authentication. The authenticated state is kept in a single shared flag on the service… | |
| Aplazada | Alta (8.8) | 0.17% | — | Pollen Robotics Reachy MiniAIHuggingface SpacesAI | 23/9/2026 | 23/9/2026 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's only dependency is Depends(get_app_manager), which just hands back the manager object from application state, so… | |
| Aplazada | Media (5.3) | 0.48% | — | Reachy MiniAI | 25/8/2026 | 9/9/2026 | Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without authentication, file-extension checks, content validation, or size validation. The… | |
| Analizada | Crítica (9.2) | 0.55% | — | Dest-unreach Socat | 25/6/2026 | 26/6/2026 | socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char… | |
| Aplazada | Media (5.3) | 0.38% | — | Hostinger ReachAI | 13/5/2026 | 17/6/2026 | The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.58% | — | Ancoratthemes UreachAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes uReach ureach allows PHP Local File Inclusion.This issue affects uReach: from n/a through <= 1.3.3. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Cleverreach WPAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.21. | |
| Aplazada | Crítica (9.9) | 0.34% | — | Elextensions Reachship Woocommerce Multi Carrier Conditional ShippingAI | 20/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping elex-reachship-multi-carrier-conditional-shipping allows Using Malicious Files.This issue affects ReachShip WooCommerce Multi-Carrier & Conditional Shipping: from n/a through <=… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Cleverreach WPAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.20. | |
| Aplazada | Alta (7.5) | 0.50% | — | CleverreachAI | 6/8/2025 | 17/6/2026 | The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.27% | — | Official Cleverreach Plugin FOR WoocommerceAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce cleverreach-wc allows Cross Site Request Forgery.This issue affects Official CleverReach Plugin for WooCommerce: from n/a through <= 3.4.6. | |
| Modificada | Alta (7.5) | 0.57% | — | Reachfargps Reachfar GPS Firmware | 10/10/2023 | 17/6/2026 | Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages, SOS device locations and device… | |
| Modificada | Media (6.4) | 0.89% | — | Hitreach Allow PHP IN Posts AND Pages | 16/9/2023 | 17/6/2026 | The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. | |
| Modificada | Media (6.5) | 1.2% | — | Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server | 20/5/2022 | 17/6/2026 | In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client… | |
| Modificada | Media (6.5) | 0.59% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended. | |
| Modificada | Media (5.4) | 0.60% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image… | |
| Modificada | Alta (7.2) | 3.6% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation… | |
| Modificada | Alta (7.8) | 0.72% | — | Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server | 16/2/2020 | 17/6/2026 | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. | |
| Modificada | Alta (7.5) | 3.9% | — | Dest-unreach Socat | 8/6/2017 | 17/6/2026 | The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash). | |
| Modificada | Media (5.3) | 2.5% | — | Dest-unreach Socat | 30/1/2017 | 17/6/2026 | The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret. | |
| Modificada | Baja (2.6) | 2.1% | — | Dest-unreach Socat | 8/5/2014 | 16/6/2026 | socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap… | |
| Modificada | Baja (1.9) | 0.40% | — | Dest-unreach SocatFedoraproject FedoraOpensuse | 4/2/2014 | 17/6/2026 | Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line. | |
| Modificada | Media (6.2) | 0.46% | — | Dest-unreach Socat | 21/6/2012 | 16/6/2026 | Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address. |