Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.1% | 💥 PoC | IBM Storage Fusion HCI | 14/5/2024 | 17/6/2026 | IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807. | |
| Aplazada | Media (4.3) | 0.53% | — | Jack Arturo WP Fusion LiteAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite allows Retrieve Embedded Sensitive Data.This issue affects WP Fusion Lite: from n/a through <= 3.42.10. | |
| Aplazada | Media (6.3) | 0.68% | — | GradioAIAutomatic1111 Stable-diffusion-webuiAI | 12/4/2024 | 17/6/2026 | stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on… | |
| Modificada | Alta (7.2) | 0.83% | — | Theme-fusion Avada | 9/4/2024 | 17/6/2026 | The Avada theme for WordPress is vulnerable to SQL Injection via the 'entry' parameter in all versions up to, and including, 7.11.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticted attackers, with… | |
| Modificada | Media (6.4) | 0.52% | — | Theme-fusion Avada | 9/4/2024 | 17/6/2026 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.11.6 via the form_to_url_action function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to… | |
| Modificada | Media (5.3) | 28% | 💥 Exploit | Theme-fusion Avada | 9/4/2024 | 17/6/2026 | The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload… | |
| Modificada | Media (5.4) | 0.69% | — | Theme-fusion Avada | 9/4/2024 | 17/6/2026 | The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Aplazada | Crítica (9.9) | 1.6% | — | Jack Arturo WP Fusion LiteAI | 3/4/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24. | |
| Modificada | Alta (8.8) | 0.74% | — | Avada Fusion Builder | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. | |
| Modificada | Alta (7.7) | 0.57% | — | Theme-fusion Avada | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | |
| Modificada | Alta (8.8) | 0.26% | — | Avada Fusion Builder | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Themefusion Fusion BuilderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through 3.11.1. | |
| Modificada | Alta (8.8) | 0.67% | — | Theme-fusion Avada | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | |
| Analizada | Alta (7.4) | 99% | ⚠ Explotación activa💥 Exploit | Adobe Coldfusion | 18/3/2024 | 17/6/2026 | ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of… | |
| Analizada | Media (5.3) | 0.53% | — | Fusionpbx | 18/3/2024 | 17/6/2026 | FusionPBX before 5.2.0 does not validate a session. | |
| Modificada | Media (6.5) | 0.66% | — | Theme-fusion Avada | 13/3/2024 | 17/6/2026 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form… | |
| Analizada | Alta (7.1) | 2.3% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Media (6.7) | 0.65% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Modificada | Media (6.7) | 3.5% | — | Vmware WorkstationVmware EsxiVmware Fusion | 5/3/2024 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained… | |
| Modificada | Alta (8.8) | 1.2% | — | Theme-fusion Avada | 29/2/2024 | 17/6/2026 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access… | |
| Analizada | Media (4.4) | 0.23% | — | Vmware FusionVmware Workstation | 29/2/2024 | 17/6/2026 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure. | |
| Modificada | Media (4.8) | 0.46% | — | Fusionpbx | 19/1/2024 | 17/6/2026 | FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product. | |
| Modificada | Media (6.8) | 0.19% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. | |
| Modificada | Media (4.6) | 0.29% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules." | |
| Modificada | Alta (8.8) | 0.31% | — | Scalefusion | 11/1/2024 | 17/6/2026 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules." |