Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.29% | — | Strongtestimonials Strong TestimonialsAI | 6/11/2025 | 7/10/2026 | The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a do_shortcode call. This makes… | |
| Aplazada | Crítica (10) | 0.36% | — | Deepseaelectronics Dse855AI | 31/10/2025 | 17/6/2026 | Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device. | |
| Aplazada | Alta (7.5) | 0.35% | — | CBK Soft Software Hardware Electronic Computer Systems Industry AND Trade INC EnvisionAI | 24/10/2025 | 17/6/2026 | Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting. This issue affects enVision: before… | |
| Aplazada | Media (5.5) | 0.17% | — | VHS Electronic Software ACE CenterAI | 20/10/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255. | |
| Aplazada | Media (4.3) | 0.28% | — | Webmaniabr Nota Fiscal Eletronica WoocommerceAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9. | |
| Aplazada | Media (5.9) | 0.24% | — | Webmaniabr Nota Fiscal Eletronica WoocommerceAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Stored XSS.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9. | |
| Analizada | Alta (7.8) | 0.24% | — | Nvidia Megatron-lm | 24/9/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.24% | — | Nvidia Megatron-lm | 24/9/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.24% | — | Nvidia Megatron-lm | 24/9/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 0.24% | — | Nvidia Megatron-lm | 24/9/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (5.3) | 0.27% | — | Wisdomgarden TronclassAI | 19/9/2025 | 17/6/2026 | Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers with regular privilege to modify a specific parameter to access other users' files. | |
| Analizada | Media (6.8) | 0.29% | — | Positron Px360bt Firmware | 15/9/2025 | 17/6/2026 | The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including… | |
| Aplazada | Media (6.8) | 0.46% | — | Crestron Touchscreens X70AI | 9/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061… | |
| Aplazada | Media (5.9) | 0.37% | — | Crestron Tsw-760AICrestron Tsw-1060AI | 9/9/2025 | 17/6/2026 | A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets prioritized by the ConsoleFindCommandMatchList. A third-party researcher discovered that the ConsoleFindCommandMatchList enumerates the… | |
| Aplazada | Media (6.1) | 0.27% | — | ElectronAI | 4/9/2025 | 17/6/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the… | |
| Aplazada | Media (6.5) | 0.17% | — | Deetronix Booking Ultra PROAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.21. | |
| Aplazada | Alta (8.6) | 0.37% | — | Crestron Touchscreens X70AICrestron Tsw-x70AICrestron Tsw-x60AICrestron Tst-1080AI+9 | 3/9/2025 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid… | |
| Aplazada | Media (5.9) | 0.16% | — | Delta Electronics DiaviewAI | 1/9/2025 | 17/6/2026 | Delta Electronics DIAView has an authentication bypass vulnerability. | |
| Aplazada | Media (5.5) | 0.18% | — | Delta Electronics EIP BuilderAI | 26/8/2025 | 17/6/2026 | Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability. | |
| Aplazada | Alta (7.8) | 0.21% | — | Delta Electronics CommgrAI | 26/8/2025 | 17/6/2026 | Delta Electronics COMMGR has Code Injection vulnerability. | |
| Aplazada | Alta (8.6) | 0.40% | — | Delta Electronics CommgrAI | 26/8/2025 | 17/6/2026 | Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability. | |
| Aplazada | Media (6.5) | 0.82% | — | Hitron Cgnf-twnAI | 25/8/2025 | 17/6/2026 | Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input validation within the telnet command handling mechanism. An attacker can exploit this vulnerability by injecting arbitrary commands through the telnet interface when prompted for… | |
| Aplazada | Crítica (9.8) | 0.66% | 💥 PoC | Voltronicpower ViewpowerAIVoltronicpower Powershield NetguardAI | 22/8/2025 | 17/6/2026 | Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system… | |
| Aplazada | Crítica (10) | 0.80% | 💥 PoC | Voltronicpower ViewpowerAIVoltronicpower Viewpower PROAIVoltronicpower Powershield NetguardAI | 22/8/2025 | 17/6/2026 | Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code… | |
| Aplazada | Alta (7) | 0.16% | — | Strongdm Macos ClientAI | 20/8/2025 | 17/6/2026 | The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message. |