Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.21% | — | Amazon Q DeveloperAIMicrosoft Visual Studio CodeAI | 30/7/2025 | 17/6/2026 | The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API… | |
| Analizada | Media (5.9) | 0.15% | — | ARM Development Studio | 22/7/2025 | 17/6/2026 | Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio. | |
| Modificada | Media (6.5) | 0.31% | — | Realtek Rtl8762e Software Development KIT | 9/7/2025 | 5/7/2026 | Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet. | |
| Analizada | Media (5.4) | 0.18% | — | Wpdeveloper Essential Addons FOR Elementor | 8/7/2025 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Media (6.5) | 0.17% | — | Mediatek Software Development KITGoogle AndroidOpenwrt | 8/7/2025 | 17/6/2026 | In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317. | |
| Modificada | Media (6.5) | 0.17% | — | Mediatek Software Development KITGoogle AndroidOpenwrt | 8/7/2025 | 17/6/2026 | In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09752821; Issue ID: MSV-3342. | |
| Analizada | Media (6.5) | 0.14% | — | Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt | 8/7/2025 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421. | |
| Analizada | Media (5.5) | 0.18% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418040; Issue ID: MSV-3476. | |
| Analizada | Media (5.5) | 0.16% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418039; Issue ID: MSV-3477. | |
| Analizada | Media (5.5) | 0.16% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418038; Issue ID: MSV-3478. | |
| Analizada | Media (5.5) | 0.16% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418048; Issue ID: MSV-3479. | |
| Analizada | Media (5.5) | 0.18% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418047; Issue ID: MSV-3480. | |
| Analizada | Alta (8.8) | 0.35% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00415570; Issue ID: MSV-3404. | |
| Analizada | Alta (8.8) | 0.35% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416226; Issue ID: MSV-3409. | |
| Analizada | Crítica (9.8) | 0.61% | — | Mediatek Software Development KIT | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416939; Issue ID: MSV-3422. | |
| Analizada | Crítica (9.8) | 0.54% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416938; Issue ID: MSV-3444. | |
| Analizada | Crítica (9.8) | 0.54% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416937; Issue ID: MSV-3445. | |
| Analizada | Crítica (9.8) | 0.61% | — | Mediatek Software Development KITOpenwrt | 8/7/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416936; Issue ID: MSV-3446. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Bestwpdeveloper Woocommerce Product Multi-actionAI | 4/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiaction allows Object Injection.This issue affects WooCommerce Product Multi-Action: from n/a through <= 1.3. | |
| Modificada | Alta (7.5) | 0.46% | — | Realtek Rtl8762e Software Development KIT | 24/6/2025 | 5/7/2026 | An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt. | |
| Analizada | Media (5.3) | 0.37% | — | Zhilink ADP Application Developer Platform | 19/6/2025 | 17/6/2026 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /adpweb/a/base/barcodeDetail/. The manipulation of the argument barcodeNo/barcode/itemNo leads to sql injection. The attack may be… | |
| Analizada | Crítica (9.8) | 0.73% | — | Blackberry QNX Software Development Platform | 10/6/2025 | 17/6/2026 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec. | |
| Analizada | Alta (7.8) | 1.6% | 💥 PoC | Microsoft Windows Software Development KIT | 10/6/2025 | 17/6/2026 | Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.4) | 0.20% | — | Wpdeveloper Essential Addons FOR Elementor | 7/6/2025 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient… | |
| Analizada | Media (5.4) | 0.20% | — | Wpdeveloper Essential Addons FOR Elementor | 7/6/2025 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input… |