Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.38%—Karel Electronics Industry AND Trade ViportAI4/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects ViPort: through 23012026.
AplazadaAlta (7.8)0.29%—Nvidia Megatron-lmAI3/2/202617/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, data tampering.
AplazadaMedia (6.5)0.29%—Strong TestimonialsAI3/2/202617/6/2026
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through <= 3.2.20.
AplazadaAlta (7.5)0.30%—Gerstrong Commander GeniusAI27/1/202617/6/2026
Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge.
AplazadaAlta (8.8)0.41%—Strongholdthemes Tech Life CPTAI22/1/202617/6/2026
Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n/a through <= 16.4.
AplazadaAlta (8.8)0.41%—Strongholdthemes Dental Care CPTAI22/1/202617/6/2026
Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental Care CPT: from n/a through <= 20.2.
AplazadaMedia (6.5)0.41%—Deetronix Booking Ultra PROAI22/1/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Retrieve Embedded Sensitive Data.This issue affects Booking Ultra Pro: from n/a through <= 1.1.23.
AplazadaMedia (6.5)0.35%—Ninetheme ElectronAI22/1/202617/6/2026
Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2.
AplazadaAlta (8.1)1.00%—StrongswanAI16/1/202617/6/2026
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
AnalizadaMedia (4.4)0.13%—Amauri Tarteaucitronjs13/1/202617/6/2026
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0.
AplazadaCrítica (9.3)0.43%—Inim Electronics Smartliving SmartlanAI8/1/202617/6/2026
INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.
AplazadaMedia (6.5)0.16%—Zookatron Mybooktable BookstoreAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.
AplazadaMedia (4.3)0.23%—Strong TestimonialsAI30/12/202517/6/2026
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated attackers with Contributor-level access and above to modify or delete…
AplazadaAlta (8.7)0.46%—Rifatron 5brid DVRAI24/12/202517/6/2026
Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.
AplazadaAlta (7.8)0.16%—Tradingview DesktopAIElectronAI23/12/202517/6/2026
TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaMedia (6.1)0.29%💥 PoCClincapture Captivate Electronic Data Capture22/12/202517/6/2026
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
ModificadaMedia (5.5)0.12%—Hitrontech Hi3120 Firmware15/12/20257/10/2026
An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html
AplazadaMedia (4.3)0.22%—IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI10/12/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers. This issue affects DijiDemi: through 28.11.2025.
AnalizadaBaja (3.1)0.18%—Medtronic Carelink Network4/12/202525/9/2026
Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.
AnalizadaMedia (4.1)0.11%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.
AnalizadaCrítica (9.8)0.33%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.
AnalizadaMedia (5.3)0.30%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.
AplazadaAlta (8.6)0.18%—TAX Service Electronic HDMAI26/11/202517/6/2026
The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements
AplazadaCrítica (9.8)0.33%—Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI19/11/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119.
AplazadaAlta (7.8)0.43%—Nvidia Megatron-lmAI11/11/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, data tampering.