Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.82%—Square WireAI16/9/202630/9/2026
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits, slices, or allocations. In Kotlin,…
AnalizadaAlta (7.5)0.73%—Squareup Wire17/7/202612/8/2026
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(), allowing a crafted protobuf varint encoding…
AplazadaMedia (6.5)0.27%—Nsquared Simply Schedule AppointmentsAI13/7/202613/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
AplazadaMedia (6.5)0.33%—Nsquared Simply Schedule AppointmentsAI13/7/202613/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.
AplazadaAlta (8.5)0.36%—Saad Iqbal Apiexperts Square FOR WoocommerceAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.
AplazadaAlta (8.3)0.32%—Saad Iqbal Apiexperts Square FOR WoocommerceAI25/6/202625/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
AplazadaMedia (4.3)0.40%—Typesquare Webfonts FOR ConahaAI20/5/202623/7/2026
The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access…
AnalizadaAlta (8.2)0.32%—CpanelCpanel WP SquaredCpanel WHM13/5/202612/8/2026
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
AnalizadaAlta (8.6)0.38%—CpanelCpanel WP SquaredCpanel WHM13/5/202612/8/2026
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
AplazadaAlta (8.5)0.36%—Saad Iqbal Apiexperts Square FOR WoocommerceAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.1.
AnalizadaCrítica (9.3)99%⚠ Explotación activaCpanelCpanel WHMCpanel WP Squared29/4/202630/9/2026
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
AplazadaMedia (5.3)0.26%—Nsquared Simply Schedule AppointmentsAI8/4/202624/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.
AplazadaAlta (8.5)0.36%—Nsquared Simply Schedule AppointmentsAI8/4/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
ModificadaAlta (8.4)0.21%—Squareapps MY Location31/3/202624/7/2026
An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AnalizadaCrítica (9.3)1.0%—Telesquare Sdt-cs3b1 Firmware16/3/202617/6/2026
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files,…
AnalizadaCrítica (9.3)0.52%—Telesquare Sdt-cs3b1 Firmware16/3/202617/6/2026
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve sensitive…
AnalizadaAlta (8.7)0.71%—Telesquare Sdt-cs3b1 Firmware16/3/202617/6/2026
Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger device reboot without authentication. Attackers can send POST requests to the lte.cgi endpoint with the Command=Reboot parameter to cause denial of service by forcing the…
AnalizadaMedia (5.3)0.29%—Telesquare Sdt-cs3b1 Firmware16/3/202617/6/2026
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting missing request validation. Attackers can craft malicious web pages that perform administrative actions when visited by logged-in…
AplazadaMedia (5.9)0.24%—Silencesoft External RSS ReaderAIAJ Square INC RSS ReaderAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Stored XSS.This issue affects Silencesoft RSS Reader: from n/a through <= 0.6.
AplazadaMedia (6.5)0.22%—Nsquared Simply Schedule AppointmentsAI22/1/202617/6/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.
AplazadaAlta (7.5)0.34%—Automattic Woocommerce SquareAI10/1/202617/6/2026
The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (credit…
AnalizadaMedia (6.1)0.20%—Centralsquare Community Development12/11/202517/6/2026
Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.
AnalizadaCrítica (9.8)0.45%—Centralsquare Community Development12/11/202517/6/2026
An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials.
AnalizadaCrítica (9.8)0.35%—Centralsquare Community Development12/11/202517/6/2026
A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.
AplazadaMedia (5.4)0.17%—AJ Square INC RSS ReaderAI26/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Side Request Forgery.This issue affects Silencesoft RSS Reader: from n/a through <= 0.6.