Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.36% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the… | |
| Aplazada | Media (6.4) | 0.42% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Opennms MeridianAIOpennms HorizonAI | 10/9/2026 | 18/9/2026 | A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "Maintenance contracts expired" (AssetManagementMaintExpired) and "Maintenance… | |
| Pendiente de análisis | Media (5.9) | 0.21% | — | Opennms MeridianAIOpennms HorizonAI | 10/9/2026 | 18/9/2026 | An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a source whose response is attacker-controlled (for example a compromised monitored host or an HTTP man-in-the-middle position), the collector's XML parser… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI | 9/9/2026 | 10/9/2026 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Live555 Streaming MediaAI | 9/9/2026 | 14/9/2026 | A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server. | |
| Aplazada | Media (5.3) | 0.24% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 14/9/2026 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build… | |
| Aplazada | Alta (7.3) | 0.12% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 18/9/2026 | VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process. | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | Nvidia Triton Inference ServerAI | 8/9/2026 | 8/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Nvidia Triton Inference ServerAI | 8/9/2026 | 8/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (8.8) | 0.48% | — | Microsoft WEB Media Extensions | 8/9/2026 | 30/9/2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.1) | 0.50% | — | Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.1) | 0.35% | — | Avideo SocialmediapublisherAIWwbn AvideoAI | 8/9/2026 | 8/9/2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored… | |
| Aplazada | Media (6.5) | 0.27% | — | Fastlinemedia Beaver BuilderAI | 8/9/2026 | 8/9/2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Analizada | Media (5.3) | 0.19% | — | Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+15 | 7/9/2026 | 9/9/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue… | |
| Analizada | Media (5.3) | 0.19% | — | Mediatek Mt2716 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 Firmware+53 | 7/9/2026 | 9/9/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue… | |
| Analizada | Alta (8.4) | 0.13% | — | Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+49 | 7/9/2026 | 9/9/2026 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | |
| Analizada | Alta (8.4) | 0.13% | — | Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+49 | 7/9/2026 | 9/9/2026 | In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | |
| Analizada | Media (5.5) | 0.09% | — | Mediatek Mt2716 FirmwareMediatek Mt6835 FirmwareMediatek Mt6858 FirmwareMediatek Mt6878 Firmware+18 | 7/9/2026 | 9/9/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232. | |
| Aplazada | Media (6.1) | 0.17% | — | Fastlinemedia Beaver BuilderAI | 5/9/2026 | 8/9/2026 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |