Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.68%—Vmware FusionVmware Workstation14/5/202417/6/2026
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
AplazadaMedia (6.1)0.40%—Oxygen XML WEB AuthorAIOxygen Content FusionAI14/5/202417/6/2026
Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.
ModificadaCrítica (9.8)3.1%💥 PoCIBM Storage Fusion HCI14/5/202417/6/2026
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
AplazadaMedia (4.3)0.53%—Jack Arturo WP Fusion LiteAI24/4/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite allows Retrieve Embedded Sensitive Data.This issue affects WP Fusion Lite: from n/a through <= 3.42.10.
AplazadaMedia (6.3)0.68%—GradioAIAutomatic1111 Stable-diffusion-webuiAI12/4/202417/6/2026
stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on…
ModificadaAlta (7.2)0.83%—Theme-fusion Avada9/4/202417/6/2026
The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticted attackers, with…
ModificadaMedia (6.4)0.52%—Theme-fusion Avada9/4/202417/6/2026
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to…
ModificadaMedia (5.3)28%💥 ExploitTheme-fusion Avada9/4/202417/6/2026
The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload…
ModificadaMedia (5.4)0.69%—Theme-fusion Avada9/4/202417/6/2026
The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above…
AplazadaCrítica (9.9)1.6%—Jack Arturo WP Fusion LiteAI3/4/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.
ModificadaAlta (8.8)0.74%—Avada Fusion Builder28/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
ModificadaAlta (7.7)0.57%—Theme-fusion Avada28/3/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
ModificadaAlta (8.8)0.26%—Avada Fusion Builder27/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
AplazadaAlta (7.1)0.39%—Themefusion Fusion BuilderAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through 3.11.1.
ModificadaAlta (8.8)0.67%—Theme-fusion Avada26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
AnalizadaAlta (7.4)99%⚠ Explotación activa💥 ExploitAdobe Coldfusion18/3/202417/6/2026
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of…
AnalizadaMedia (5.3)0.53%—Fusionpbx18/3/202417/6/2026
FusionPBX before 5.2.0 does not validate a session.
ModificadaMedia (6.5)0.66%—Theme-fusion Avada13/3/202417/6/2026
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form…
AnalizadaAlta (7.1)2.3%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
AnalizadaMedia (6.7)0.65%—Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained…
ModificadaMedia (6.7)3.5%—Vmware WorkstationVmware EsxiVmware Fusion5/3/202417/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained…
ModificadaAlta (8.8)1.2%—Theme-fusion Avada29/2/202417/6/2026
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access…
AnalizadaMedia (4.4)0.23%—Vmware FusionVmware Workstation29/2/202417/6/2026
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
ModificadaMedia (4.8)0.46%—Fusionpbx19/1/202417/6/2026
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
ModificadaMedia (6.8)0.19%—Scalefusion11/1/202417/6/2026
ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.