Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.19% | — | Anibalwainstein Effect MakerAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Effect Maker effect-maker allows DOM-Based XSS.This issue affects Effect Maker: from n/a through <= 1.2.1. | |
| Aplazada | Media (5.1) | 0.52% | — | Fibaro System Home CenterAI | 6/1/2026 | 17/6/2026 | FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content. | |
| Modificada | Alta (8.6) | 0.93% | — | Thibaud-rohmer Photoshow | 22/12/2025 | 17/6/2026 | PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload… | |
| Analizada | Media (4.3) | 0.23% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries. | |
| Analizada | Media (6.5) | 0.31% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request. | |
| Analizada | Media (6.1) | 0.22% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator. | |
| Analizada | Media (4.3) | 0.19% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request. | |
| Analizada | Media (6.1) | 0.25% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation. | |
| Analizada | Media (5.4) | 0.18% | — | Elastic Kibana | 15/12/2025 | 7/10/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection. | |
| Analizada | Media (4.3) | 0.21% | — | Elastic Kibana | 12/11/2025 | 17/6/2026 | Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant. | |
| Aplazada | Media (6.5) | 0.22% | — | Anibalwainstein Effect MakerAI | 6/11/2025 | 7/10/2026 | Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Effect Maker: from n/a through <= 1.2.1. | |
| Analizada | Media (5.5) | 0.17% | — | Libarchive | 5/11/2025 | 17/6/2026 | An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). | |
| Analizada | Media (5.4) | 0.23% | — | Elastic Kibana | 10/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS) | |
| Analizada | Media (6.1) | 0.27% | — | Elastic Kibana | 10/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS) | |
| Analizada | Media (5.4) | 0.24% | — | Elastic Kibana | 7/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. | |
| Aplazada | Media (5.7) | 0.16% | — | LibavAIFfmpegAI | 6/10/2025 | 17/6/2026 | When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than MAX_DURATION_BUFFER_SIZE bytes (0x100000) for example 0x101000 bytes, then at [0] we have size =… | |
| Modificada | Alta (8.8) | 0.50% | — | Dolibarr Erp/crm | 1/10/2025 | 5/7/2026 | Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter. | |
| Aplazada | Media (5.9) | 0.22% | — | Thetechtribe THE TribalAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thetechtribe The Tribal the-tech-tribe allows Stored XSS.This issue affects The Tribal: from n/a through <= 1.3.3. | |
| Aplazada | Media (5.3) | 0.31% | — | Thetechtribe THE TribalAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | Whuan132 AibatteryAI | 18/9/2025 | 17/6/2026 | A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIBatteryHelper/XPC/BatteryXPCService.swift of the component com.collweb.AIBatteryHelper. The manipulation results in missing authentication. The attack requires a local approach. The exploit has been… | |
| Analizada | Media (6.5) | 0.28% | — | Elastic Kibana | 28/8/2025 | 17/6/2026 | Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces. | |
| Aplazada | Crítica (9.4) | 4.4% | 💥 Exploit | Dolibarr ERP CRMAI | 13/8/2025 | 16/6/2026 | Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the… | |
| Analizada | Baja (1.9) | 0.24% | — | Libav | 5/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit… | |
| Analizada | Baja (1.9) | 0.22% | — | Libav | 5/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Attacking locally is a requirement. The exploit has been disclosed to the public and… | |
| Analizada | Baja (1.9) | 0.22% | — | Libav | 5/8/2025 | 17/6/2026 | A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has… |