Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.21%—Amazon Q DeveloperAIMicrosoft Visual Studio CodeAI30/7/202517/6/2026
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API…
AnalizadaMedia (5.9)0.15%—ARM Development Studio22/7/202517/6/2026
Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.
ModificadaMedia (6.5)0.31%—Realtek Rtl8762e Software Development KIT9/7/20255/7/2026
Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.
AnalizadaMedia (5.4)0.18%—Wpdeveloper Essential Addons FOR Elementor8/7/202517/6/2026
The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This…
ModificadaMedia (6.5)0.17%—Mediatek Software Development KITGoogle AndroidOpenwrt8/7/202517/6/2026
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317.
ModificadaMedia (6.5)0.17%—Mediatek Software Development KITGoogle AndroidOpenwrt8/7/202517/6/2026
In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09752821; Issue ID: MSV-3342.
AnalizadaMedia (6.5)0.14%—Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt8/7/202517/6/2026
In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421.
AnalizadaMedia (5.5)0.18%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418040; Issue ID: MSV-3476.
AnalizadaMedia (5.5)0.16%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418039; Issue ID: MSV-3477.
AnalizadaMedia (5.5)0.16%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418038; Issue ID: MSV-3478.
AnalizadaMedia (5.5)0.16%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418048; Issue ID: MSV-3479.
AnalizadaMedia (5.5)0.18%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418047; Issue ID: MSV-3480.
AnalizadaAlta (8.8)0.35%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00415570; Issue ID: MSV-3404.
AnalizadaAlta (8.8)0.35%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416226; Issue ID: MSV-3409.
AnalizadaCrítica (9.8)0.61%—Mediatek Software Development KIT8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416939; Issue ID: MSV-3422.
AnalizadaCrítica (9.8)0.54%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416938; Issue ID: MSV-3444.
AnalizadaCrítica (9.8)0.54%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416937; Issue ID: MSV-3445.
AnalizadaCrítica (9.8)0.61%—Mediatek Software Development KITOpenwrt8/7/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416936; Issue ID: MSV-3446.
AplazadaCrítica (9.8)0.44%—Bestwpdeveloper Woocommerce Product Multi-actionAI4/7/202517/6/2026
Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiaction allows Object Injection.This issue affects WooCommerce Product Multi-Action: from n/a through <= 1.3.
ModificadaAlta (7.5)0.46%—Realtek Rtl8762e Software Development KIT24/6/20255/7/2026
An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.
AnalizadaMedia (5.3)0.37%—Zhilink ADP Application Developer Platform19/6/202517/6/2026
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /adpweb/a/base/barcodeDetail/. The manipulation of the argument barcodeNo/barcode/itemNo leads to sql injection. The attack may be…
AnalizadaCrítica (9.8)0.73%—Blackberry QNX Software Development Platform10/6/202517/6/2026
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.
AnalizadaAlta (7.8)1.6%💥 PoCMicrosoft Windows Software Development KIT10/6/202517/6/2026
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.4)0.20%—Wpdeveloper Essential Addons FOR Elementor7/6/202517/6/2026
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 due to insufficient…
AnalizadaMedia (5.4)0.20%—Wpdeveloper Essential Addons FOR Elementor7/6/202517/6/2026
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insufficient input…