Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1294 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Jacob Allred Infusionsoft WEB Form JavascriptAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infusionsoft Web Form JavaScript infusionsoft-web-form-javascript allows Stored XSS.This issue affects Infusionsoft Web Form JavaScript: from n/a through <= 1.1.1.
AplazadaMedia (6.5)0.26%—Agency Dominion INC FusionAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion allows DOM-Based XSS.This issue affects Fusion: from n/a through <= 1.6.4.
AplazadaMedia (6.5)0.21%—Formlift FOR Infusionsoft WEB FormsAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms formlift allows Stored XSS.This issue affects FormLift for Infusionsoft Web Forms: from n/a through <= 7.5.19.
AnalizadaMedia (6.5)0.84%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application.
AnalizadaMedia (6.1)0.42%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's…
AnalizadaMedia (6.5)0.82%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server…
AnalizadaCrítica (9.6)0.41%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join,…
AnalizadaMedia (6.1)0.83%💥 ExploitAutomatic1111 Stable-diffusion-webui20/3/202517/6/2026
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.
ModificadaAlta (7.5)0.82%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive…
AnalizadaMedia (6)1.8%⚠ Explotación activaVmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+24/3/202517/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
AnalizadaCrítica (9.8)2.3%💥 PoCTheme-fusion Avada13/2/202517/6/2026
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…
AnalizadaCrítica (9.8)0.55%—Theme-fusion Avada Builder13/2/202517/6/2026
The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers…
AplazadaAlta (7.5)0.44%—Syncfusion Ej2-spreadsheetAI5/2/202517/6/2026
A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. NOTE: the Supplier disputes this because they found that the lib.setValue function is not utilized.
AnalizadaMedia (6.5)0.23%—IBM Storage FusionIBM Storage Fusion HCIIBM Storage Fusion HCI FOR Watsonx28/1/202517/6/2026
IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.
AnalizadaMedia (5.4)0.22%—Nfusionsolutions Precious Metals Charts AND Widgets24/1/202517/6/2026
The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nfusion-widget' shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
AnalizadaMedia (5.4)0.22%—Theme-fusion Avada Builder22/1/202517/6/2026
The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.43%—Huawei Fusioncompute27/12/202417/6/2026
There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to compromise module service. (Vulnerability ID: HWPSIRT-2020-05010) This vulnerability…
AnalizadaAlta (7.8)0.11%—Huawei Fusioncompute27/12/202417/6/2026
There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common…
AnalizadaMedia (4.3)0.38%—Theme-fusion Avada Builder25/12/202417/6/2026
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the 'fusion_blog' shortcode and due to insufficient restrictions on which posts can be included. This makes it possible for authenticated…
AnalizadaAlta (8.1)14%—Adobe Coldfusion23/12/202417/6/2026
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted…
AplazadaMedia (6.5)0.24%—Agency Dominion INC FusionAI19/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion.This issue affects Fusion: from n/a through <= 1.6.1.
ModificadaMedia (4.3)0.18%—Theme-fusion Avada16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
AplazadaCrítica (9.1)0.63%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.
AplazadaAlta (7.5)0.52%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.
AplazadaCrítica (9.1)0.56%—Fusion Chat Chat AI Assistant ASK ME AnythingAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
Orbitaley — Vulnerabilidades