Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.29% | — | Developer FormatterAI | 6/6/2025 | 17/6/2026 | The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2015.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Analizada | Crítica (9.8) | 0.77% | — | OpenwrtMediatek Software Development KIT | 2/6/2025 | 17/6/2026 | In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303. | |
| Analizada | Media (6.1) | 0.27% | — | Gearside Developer Dashboard | 30/5/2025 | 17/6/2026 | The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (5.3) | 0.50% | — | Zhilink ADP Application Developer Platform | 29/5/2025 | 17/6/2026 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /adpweb/wechat/verifyToken/. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.51% | — | Zhilink ADP Application Developer Platform | 29/5/2025 | 17/6/2026 | A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /adpweb/a/ica/api/service/rfa/testService. The manipulation leads to improper neutralization of special elements… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper Essential BlocksAI | 27/5/2025 | 17/6/2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider and Post Carousel widgets in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (6.1) | 0.29% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. | |
| Analizada | Media (6.5) | 0.58% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 14/5/2025 | 17/6/2026 | Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 14/5/2025 | 17/6/2026 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.55% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 14/5/2025 | 17/6/2026 | NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (8.2) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (7) | 0.15% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM 4769 Developers Toolkit | 12/5/2025 | 17/6/2026 | IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due to improper memory allocation of an excessive size. | |
| Modificada | Media (6.5) | 0.70% | — | Apple Airplay Audio Software Development KITApple Airplay Video Software Development KITApple Carplay Communication Plug-in | 30/4/2025 | 17/6/2026 | A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination. | |
| Modificada | Media (6.5) | 3.2% | 💥 PoC | Apple Airplay Audio Software Development KITApple Airplay Video Software Development KITApple Carplay Communication Plug-in | 30/4/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination. | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Wpdeveloper Essential Addons FOR Elementor | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Reflected XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.14. | |
| Modificada | Media (6.5) | 0.32% | — | Wpdeveloper Essential Addons FOR Elementor | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.1.9. | |
| Modificada | Media (4.3) | 0.42% | — | Wpdeveloper Essential Addons FOR Elementor | 16/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Retrieve Embedded Sensitive Data.This issue affects Essential Addons for Elementor: from n/a through <= 6.1.9. | |
| Aplazada | Media (5.3) | 0.39% | — | Developer ToolbarAI | 12/4/2025 | 17/6/2026 | The Developer Toolbar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file. | |
| Analizada | Media (5.5) | 0.25% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.25% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… |