Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.18% | — | CleantalkAI | 9/9/2026 | 9/9/2026 | The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being passed to WordPress's shortcode engine, allowing any visitor to have arbitrary shortcodes registered on the site executed server-side and rendered to every subsequent visitor of the page. | |
| Aplazada | Alta (7.2) | 0.47% | — | Cleantalk Spam Protection Honeypot Anti SpamAI | 5/9/2026 | 8/9/2026 | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.8) | 0.93% | — | EsotalkAI | 4/9/2026 | 9/9/2026 | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components | |
| Aplazada | Crítica (9.3) | 2.6% | — | SadtalkerAIFfmpegAI | 4/9/2026 | 10/9/2026 | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system… | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Rockwellautomation Factorytalk Activation ManagerAI | 1/9/2026 | 1/9/2026 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack… | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. | |
| Pendiente de análisis | Alta (8.6) | 0.31% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device. | |
| Aplazada | Crítica (10) | 1.6% | — | UI Unifi TalkAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Cleantalk Security AND Malware ScanAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | |
| Aplazada | Alta (7.5) | 0.45% | — | NetatalkAI | 17/8/2026 | 9/9/2026 | Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction.… | |
| Aplazada | Alta (7.5) | 0.45% | — | NetatalkAI | 14/8/2026 | 18/9/2026 | Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction.… | |
| Analizada | Alta (7.5) | 0.34% | — | Apple Servicetalk | 12/8/2026 | 3/9/2026 | ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cleantalk Spam ProtectionAICleantalk AntispamAICleantalk FirewallAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |
| Pendiente de análisis | Alta (8.4) | 0.53% | — | Rockwellautomation Factorytalk Datamosaix Private CloudAI | 14/7/2026 | 14/7/2026 | A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on… | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Rockwellautomation Factorytalk Services PlatformAI | 14/7/2026 | 14/7/2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and… | |
| Analizada | Media (6.1) | 0.26% | — | Cleantalk Anti-spam | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1. | |
| Analizada | Alta (8.1) | 0.39% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application. | |
| Analizada | Alta (7.5) | 0.37% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints. | |
| Analizada | Crítica (9.9) | 0.49% | — | UI Unifi Talk Application | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. | |
| Pendiente de análisis | Crítica (9.2) | 0.29% | — | Rockwellautomation Factorytalk Historian Site EditionAI | 16/6/2026 | 30/9/2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. | |
| Aplazada | Alta (8.8) | 0.51% | — | Anti Spam BY CleantalkAI | 10/6/2026 | 23/7/2026 | The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators)… | |
| Aplazada | Media (5.3) | 0.20% | — | HellotalkAI | 5/6/2026 | 17/6/2026 | HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.) | |
| Aplazada | Baja (3.7) | 0.27% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions. | |
| Aplazada | Baja (3.7) | 0.39% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI session options. | |
| Aplazada | Baja (3.7) | 0.39% | — | NetatalkAI | 21/5/2026 | 23/7/2026 | Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths. |