Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 1.8% | — | Adobe Coldfusion | 8/4/2025 | 17/6/2026 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this issue does not require user interaction, but admin panel privileges are required, and scope is changed. | |
| Analizada | Media (5.4) | 0.28% | — | Theme-fusion Avada Builder | 1/4/2025 | 17/6/2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 3.11.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.22% | — | Jacob Allred Infusionsoft WEB Form JavascriptAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infusionsoft Web Form JavaScript infusionsoft-web-form-javascript allows Stored XSS.This issue affects Infusionsoft Web Form JavaScript: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Agency Dominion INC FusionAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion allows DOM-Based XSS.This issue affects Fusion: from n/a through <= 1.6.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Formlift FOR Infusionsoft WEB FormsAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms formlift allows Stored XSS.This issue affects FormLift for Infusionsoft Web Forms: from n/a through <= 7.5.19. | |
| Analizada | Media (6.5) | 0.84% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application. | |
| Analizada | Media (6.1) | 0.42% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's… | |
| Analizada | Media (6.5) | 0.82% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server… | |
| Analizada | Crítica (9.6) | 0.41% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join,… | |
| Analizada | Media (6.1) | 0.83% | 💥 Exploit | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials. | |
| Modificada | Alta (7.5) | 0.82% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive… | |
| Analizada | Media (6) | 1.8% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+2 | 4/3/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Crítica (9.8) | 2.3% | 💥 PoC | Theme-fusion Avada | 13/2/2025 | 17/6/2026 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Analizada | Crítica (9.8) | 0.55% | — | Theme-fusion Avada Builder | 13/2/2025 | 17/6/2026 | The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.44% | — | Syncfusion Ej2-spreadsheetAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. NOTE: the Supplier disputes this because they found that the lib.setValue function is not utilized. | |
| Analizada | Media (6.5) | 0.23% | — | IBM Storage FusionIBM Storage Fusion HCIIBM Storage Fusion HCI FOR Watsonx | 28/1/2025 | 17/6/2026 | IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection. | |
| Analizada | Media (5.4) | 0.22% | — | Nfusionsolutions Precious Metals Charts AND Widgets | 24/1/2025 | 17/6/2026 | The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nfusion-widget' shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Analizada | Media (5.4) | 0.22% | — | Theme-fusion Avada Builder | 22/1/2025 | 17/6/2026 | The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.43% | — | Huawei Fusioncompute | 27/12/2024 | 17/6/2026 | There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to compromise module service. (Vulnerability ID: HWPSIRT-2020-05010) This vulnerability… | |
| Analizada | Alta (7.8) | 0.11% | — | Huawei Fusioncompute | 27/12/2024 | 17/6/2026 | There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common… | |
| Analizada | Media (4.3) | 0.38% | — | Theme-fusion Avada Builder | 25/12/2024 | 17/6/2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the 'fusion_blog' shortcode and due to insufficient restrictions on which posts can be included. This makes it possible for authenticated… | |
| Analizada | Alta (8.1) | 14% | — | Adobe Coldfusion | 23/12/2024 | 17/6/2026 | ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted… | |
| Aplazada | Media (6.5) | 0.24% | — | Agency Dominion INC FusionAI | 19/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion.This issue affects Fusion: from n/a through <= 1.6.1. | |
| Modificada | Media (4.3) | 0.18% | — | Theme-fusion Avada | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10. | |
| Aplazada | Crítica (9.1) | 0.63% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714. |