Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

5178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.58%—Phpgurukul Medical Card System17/3/202517/6/2026
A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been classified as critical. This affects an unknown part of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaAlta (8.7)0.61%—Logicaldoc14/3/202517/6/2026
The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at…
ModificadaAlta (8.6)0.57%—Logicaldoc14/3/202526/8/2026
The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attack. Exploitation of this vulnerability…
AnalizadaMedia (6.4)0.27%—Logicaldoc14/3/202517/6/2026
There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to…
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Advance SteelAutodesk Civil 3DAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3DAutodesk Civil 3D+513/3/202517/6/2026
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.28%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.28%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.25%—Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+513/3/202517/6/2026
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AplazadaMedia (6.3)0.31%—Radicaldesigns RadslideAI3/3/202517/6/2026
Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects radSLIDE: from n/a through <= 2.1.
ModificadaMedia (5.9)41%💥 PoCOpenbsd OpensshCanonical Ubuntu LinuxDebian Linux28/2/202530/6/2026
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled…
AplazadaMedia (5.3)0.29%—Quanticalabs Medicenter - Health Medical ClinicAI18/2/202517/6/2026
Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical Clinic: from n/a through < 14.7.
AplazadaMedia (4.3)0.43%—Namedical Medical Addon FOR ElementorAI4/2/202517/6/2026
The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the 'namedical_elementor_template' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
AnalizadaMedia (4.9)0.63%—Canonical Juju31/1/202517/6/2026
An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.
AnalizadaCrítica (9.8)0.74%—Gnome-remote-desktopCanonical Ubuntu Linux31/1/202517/6/2026
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
AnalizadaBaja (3.1)0.34%—Canonical Apport31/1/202517/6/2026
gdbus setgid privilege escalation
AnalizadaAlta (7.5)0.40%—Canonical Apport31/1/202517/6/2026
Users can consume unlimited disk space in /var/crash
ModificadaMedia (5.4)0.31%—Stockdio Historical Chart30/1/202517/6/2026
The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockdio-historical-chart' shortcode in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.4)0.34%—Automatically Hierarchic Categories IN MenuAI30/1/202517/6/2026
The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…