Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.19%—Anibalwainstein Effect MakerAI8/1/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Effect Maker effect-maker allows DOM-Based XSS.This issue affects Effect Maker: from n/a through <= 1.2.1.
AplazadaMedia (5.1)0.52%—Fibaro System Home CenterAI6/1/202617/6/2026
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.
ModificadaAlta (8.6)0.93%—Thibaud-rohmer Photoshow22/12/202517/6/2026
PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload…
AnalizadaMedia (4.3)0.23%—Elastic Kibana18/12/202517/6/2026
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.
AnalizadaMedia (6.5)0.31%—Elastic Kibana18/12/202517/6/2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request.
AnalizadaMedia (6.1)0.22%—Elastic Kibana18/12/202517/6/2026
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.
AnalizadaMedia (4.3)0.19%—Elastic Kibana18/12/202517/6/2026
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request.
AnalizadaMedia (6.1)0.25%—Elastic Kibana18/12/202517/6/2026
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation.
AnalizadaMedia (5.4)0.18%—Elastic Kibana15/12/20257/10/2026
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
AnalizadaMedia (4.3)0.21%—Elastic Kibana12/11/202517/6/2026
Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.
AplazadaMedia (6.5)0.22%—Anibalwainstein Effect MakerAI6/11/20257/10/2026
Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Effect Maker: from n/a through <= 1.2.1.
AnalizadaMedia (5.5)0.17%—Libarchive5/11/202517/6/2026
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
AnalizadaMedia (5.4)0.23%—Elastic Kibana10/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
AnalizadaMedia (6.1)0.27%—Elastic Kibana10/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
AnalizadaMedia (5.4)0.24%—Elastic Kibana7/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
AplazadaMedia (5.7)0.16%—LibavAIFfmpegAI6/10/202517/6/2026
When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than MAX_DURATION_BUFFER_SIZE bytes (0x100000) for example 0x101000 bytes, then at [0] we have size =…
ModificadaAlta (8.8)0.50%—Dolibarr Erp/crm1/10/20255/7/2026
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
AplazadaMedia (5.9)0.22%—Thetechtribe THE TribalAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thetechtribe The Tribal the-tech-tribe allows Stored XSS.This issue affects The Tribal: from n/a through <= 1.3.3.
AplazadaMedia (5.3)0.31%—Thetechtribe THE TribalAI26/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.3.
AplazadaAlta (7.1)0.22%—Whuan132 AibatteryAI18/9/202517/6/2026
A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCService.swift of the component com.collweb.AIBatteryHelper. The manipulation results in missing authentication. The attack requires a local approach. The exploit has been…
AnalizadaMedia (6.5)0.28%—Elastic Kibana28/8/202517/6/2026
Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.
AplazadaCrítica (9.4)4.4%💥 ExploitDolibarr ERP CRMAI13/8/202516/6/2026
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the…
AnalizadaBaja (1.9)0.24%—Libav5/8/202517/6/2026
A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit…
AnalizadaBaja (1.9)0.22%—Libav5/8/202517/6/2026
A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Attacking locally is a requirement. The exploit has been disclosed to the public and…
AnalizadaBaja (1.9)0.22%—Libav5/8/202517/6/2026
A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has…
Orbitaley — Vulnerabilidades