Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.39% | — | Lychee Link Checking ActionAILycheeorg LycheeAI | 28/8/2025 | 26/9/2026 | lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2. | |
| Aplazada | Baja (2.7) | 0.59% | — | Rubyonrails Active RecordAI | 13/8/2025 | 17/6/2026 | Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2,… | |
| Aplazada | Media (6.4) | 0.24% | — | Qodeinteractive QI Addons FOR ElementorAI | 2/8/2025 | 17/6/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 1.7% | 💥 Exploit | Synactis PDF In-the-boxAI | 1/8/2025 | 16/6/2026 | A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy operation overwrites a saved TRegistry class… | |
| Aplazada | Baja (3.5) | 0.20% | — | HPE Telco Service ActivatorAI | 31/7/2025 | 17/6/2026 | Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product | |
| Aplazada | Baja (3.5) | 0.20% | — | HPE Telco Service ActivatorAI | 31/7/2025 | 17/6/2026 | Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product | |
| Aplazada | Crítica (9.1) | 0.61% | 💥 PoC | Tj-actions Branch-namesAI | 26/7/2025 | 17/6/2026 | tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names' GitHub Action workflow which allows arbitrary command execution in… | |
| Aplazada | Alta (8.6) | 0.93% | — | Apache ActivemqAIHanwha-security Smart Security ManagerAI | 25/7/2025 | 17/6/2026 | A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port 8161). An attacker can exploit this flaw through a Cross-Origin Resource Sharing… | |
| Analizada | Alta (8.6) | 0.17% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and 8036. | |
| Analizada | Alta (7.1) | 0.25% | — | Broadcom Brocade Active Support Connectivity Gateway | 17/7/2025 | 17/6/2026 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure. | |
| Aplazada | Media (6.5) | 0.22% | — | Activity-log.com Profiler - What Slowing Down Your WPAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Profiler - What Slowing Down Your WP: from n/a through 1.0.0. | |
| Analizada | Crítica (9.8) | 0.82% | — | Mescius Activereports.net | 7/7/2025 | 17/6/2026 | Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit this vulnerability but… | |
| Analizada | Crítica (9.8) | 0.82% | — | Mescius Activereports.net | 7/7/2025 | 17/6/2026 | Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit this vulnerability but attack… | |
| Aplazada | Crítica (9.8) | 0.44% | — | Bestwpdeveloper Woocommerce Product Multi-actionAI | 4/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiaction allows Object Injection.This issue affects WooCommerce Product Multi-Action: from n/a through <= 1.3. | |
| Aplazada | Alta (7.5) | 0.62% | — | Lcweb Privatecontent - Mail ActionsAI | 4/7/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail Actions allows PHP Local File Inclusion. This issue affects PrivateContent - Mail Actions: from n/a through 2.3.2. | |
| Aplazada | Baja (2.1) | 0.15% | — | Active MailAI | 2/7/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerability is exploited, unintended E-mail may be sent when a user accesses a specially crafted URL while being logged in. | |
| Aplazada | Media (5.1) | 0.23% | — | Active MailAI | 2/7/2025 | 17/6/2026 | Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerability is exploited, an arbitrary script may be executed on the logged-in user's web browser when the user is accessing a specially crafted URL. | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Analizada | Media (5.4) | 0.26% | — | Qodeinteractive QI Addons FOR Elementor | 28/6/2025 | 17/6/2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Crítica (10) | 7.5% | — | Acti Network Video RecorderAI | 26/6/2025 | 17/6/2026 | A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via crafted HTTP requests. These commands are… | |
| Aplazada | Baja (2.1) | 0.51% | — | Hansonwang99 Spring-boot-in-actionAI | 16/6/2025 | 17/6/2026 | A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Affected by this vulnerability is the function watermarkTest of the file /springbt_watermark/src/main/java/cn/codesheep/springbt_watermark/service/ImageUploadService.java of… | |
| Aplazada | Media (5.3) | 0.41% | — | Actions ToolkitAI | 9/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Grill AND Chow | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6. | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Grandprix | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6. | |
| Modificada | Crítica (9.8) | 0.60% | — | Qodeinteractive Mediclinic | 9/6/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1. |