Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.38% | — | Karel Electronics Industry AND Trade ViportAI | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects ViPort: through 23012026. | |
| Aplazada | Alta (7.8) | 0.29% | — | Nvidia Megatron-lmAI | 3/2/2026 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, data tampering. | |
| Aplazada | Media (6.5) | 0.29% | — | Strong TestimonialsAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through <= 3.2.20. | |
| Aplazada | Alta (7.5) | 0.30% | — | Gerstrong Commander GeniusAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge. | |
| Aplazada | Alta (8.8) | 0.41% | — | Strongholdthemes Tech Life CPTAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n/a through <= 16.4. | |
| Aplazada | Alta (8.8) | 0.41% | — | Strongholdthemes Dental Care CPTAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental Care CPT: from n/a through <= 20.2. | |
| Aplazada | Media (6.5) | 0.41% | — | Deetronix Booking Ultra PROAI | 22/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Retrieve Embedded Sensitive Data.This issue affects Booking Ultra Pro: from n/a through <= 1.1.23. | |
| Aplazada | Media (6.5) | 0.35% | — | Ninetheme ElectronAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2. | |
| Aplazada | Alta (8.1) | 1.00% | — | StrongswanAI | 16/1/2026 | 17/6/2026 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow. | |
| Analizada | Media (4.4) | 0.13% | — | Amauri Tarteaucitronjs | 13/1/2026 | 17/6/2026 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Inim Electronics Smartliving SmartlanAI | 8/1/2026 | 17/6/2026 | INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models. | |
| Aplazada | Media (6.5) | 0.16% | — | Zookatron Mybooktable BookstoreAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Strong TestimonialsAI | 30/12/2025 | 17/6/2026 | The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated attackers with Contributor-level access and above to modify or delete… | |
| Aplazada | Alta (8.7) | 0.46% | — | Rifatron 5brid DVRAI | 24/12/2025 | 17/6/2026 | Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication. | |
| Aplazada | Alta (7.8) | 0.16% | — | Tradingview DesktopAIElectronAI | 23/12/2025 | 17/6/2026 | TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Media (6.1) | 0.29% | 💥 PoC | Clincapture Captivate Electronic Data Capture | 22/12/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser. | |
| Modificada | Media (5.5) | 0.12% | — | Hitrontech Hi3120 Firmware | 15/12/2025 | 7/10/2026 | An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html | |
| Aplazada | Media (4.3) | 0.22% | — | IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI | 10/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers. This issue affects DijiDemi: through 28.11.2025. | |
| Analizada | Baja (3.1) | 0.18% | — | Medtronic Carelink Network | 4/12/2025 | 25/9/2026 | Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025. | |
| Analizada | Media (4.1) | 0.11% | — | Medtronic Carelink Network | 4/12/2025 | 25/9/2026 | Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025. | |
| Analizada | Crítica (9.8) | 0.33% | — | Medtronic Carelink Network | 4/12/2025 | 25/9/2026 | Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025. | |
| Analizada | Media (5.3) | 0.30% | — | Medtronic Carelink Network | 4/12/2025 | 25/9/2026 | Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025. | |
| Aplazada | Alta (8.6) | 0.18% | — | TAX Service Electronic HDMAI | 26/11/2025 | 17/6/2026 | The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements | |
| Aplazada | Crítica (9.8) | 0.33% | — | Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119. | |
| Aplazada | Alta (7.8) | 0.43% | — | Nvidia Megatron-lmAI | 11/11/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, data tampering. |