Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.28% | — | Nvidia Megatron-lm | 24/6/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information Disclosure and Data Tampering. | |
| Analizada | Alta (7.8) | 0.28% | — | Nvidia Megatron-lm | 24/6/2025 | 17/6/2026 | NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information Disclosure and Data Tampering. | |
| Aplazada | Crítica (9.3) | 1.6% | 💥 Exploit | Aquatronica Controller SystemAI | 20/6/2025 | 17/6/2026 | An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including… | |
| Analizada | Media (4.7) | 0.38% | — | Amauri Tarteaucitron.io | 18/6/2025 | 17/6/2026 | The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. | |
| Aplazada | Alta (8.1) | 0.84% | — | Zagg Electronics AccessoriesAI | 14/6/2025 | 17/6/2026 | The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. This makes it… | |
| Aplazada | Media (5.9) | 0.26% | — | Deetronix Booking Ultra PROAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.20. | |
| Aplazada | Media (6.9) | 0.23% | — | Lantronix Device InstallerAI | 22/5/2025 | 17/6/2026 | Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or… | |
| Analizada | Media (6.1) | 0.17% | — | Couleurcitron Tarteaucitron-wp | 15/5/2025 | 17/6/2026 | The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Media (5.4) | 0.30% | — | Couleurcitron Tarteaucitron-wp | 15/5/2025 | 17/6/2026 | The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Alta (8.7) | 0.38% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Crítica (10) | 0.29% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Media (5.3) | 0.43% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. There is no visible indication when the system is recording and recording can be enabled remotely via a network API. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Media (5.1) | 0.44% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Misuse. When Enable Debug Images in Crestron Automate VX is active, snapshots of the captured video or portions thereof are stored locally on the system, and there is no visible indication that this is… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Itel Electronics IP StreamAI | 18/4/2025 | 17/6/2026 | Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges. | |
| Aplazada | Media (5.4) | 0.33% | — | Itron WP LoggerAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in iTRON WP Logger wp-data-logger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Logger: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | Deetronix Booking Ultra PROAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Reflected XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.19. | |
| Aplazada | Crítica (9.8) | 0.72% | — | Delta Electronics CommgrAI | 16/4/2025 | 17/6/2026 | Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code. | |
| Analizada | Alta (7.2) | 2.4% | — | Extron SMP 111 FirmwareExtron SMP 351 FirmwareExtron SMP 352 FirmwareExtron SME 211 Firmware | 15/4/2025 | 17/6/2026 | A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system. | |
| Analizada | Media (4.8) | 0.35% | — | Amauri TarteaucitronjsTacjs Project Tacjs | 7/4/2025 | 17/6/2026 | tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was… | |
| Analizada | Media (6.6) | 0.34% | — | Amauri Tarteaucitronjs | 7/4/2025 | 17/6/2026 | tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to… | |
| Analizada | Media (6.6) | 0.26% | — | Amauri Tarteaucitronjs | 7/4/2025 | 17/6/2026 | tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to… | |
| Aplazada | Baja (1) | 0.20% | — | ElectronAIArduino IDEAIEclipse TheiaAI | 2/4/2025 | 17/6/2026 | Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Preferences -> Settings… | |
| Aplazada | Alta (7.6) | 0.25% | — | Elfatek Elektronics Anka Jpd-00028AI | 19/3/2025 | 17/6/2026 | Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. This issue affects ANKA JPD-00028: before V.01.01. | |
| Aplazada | Baja (2.4) | 0.19% | — | SAP Electronic InvoicingAI | 11/3/2025 | 17/6/2026 | The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. By executing the specific ABAP method within the ABAP system, an unauthorized attacker could call each transaction and view the inbound… | |
| Aplazada | Media (5.3) | 0.38% | — | Beijing Founder Electronics Founder Enjoys All-media Acquisition AND Editing SystemAI | 9/3/2025 | 17/6/2026 | A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affected by this issue is the function electricDocList of the file /newsedit/report/reportCenter.do. The manipulation of the argument fvID/catID leads to sql injection. The… |