Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.24% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (6.5) | 0.40% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 8/4/2025 | 17/6/2026 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.42% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 8/4/2025 | 17/6/2026 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (5.5) | 0.16% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop | 8/4/2025 | 17/6/2026 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. | |
| Modificada | Media (5.2) | 0.24% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 8/4/2025 | 17/6/2026 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. | |
| Modificada | Media (5.2) | 0.26% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 8/4/2025 | 17/6/2026 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. | |
| Analizada | Alta (7.5) | 0.54% | — | Mediatek Software Development KITMediatek Mt7915Mediatek Mt7916Mediatek Mt7981+3 | 7/4/2025 | 17/6/2026 | In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406217; Issue ID: MSV-2773. | |
| Analizada | Alta (7.5) | 0.54% | — | Mediatek Software Development KITMediatek Mt7915Mediatek Mt7916Mediatek Mt7981+1 | 7/4/2025 | 17/6/2026 | In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00408868; Issue ID: MSV-3031. | |
| Analizada | Crítica (9.8) | 0.81% | — | Mediatek Software Development KITMediatek Mt7622Mediatek Mt7915Mediatek Mt7916+4 | 7/4/2025 | 17/6/2026 | In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875. | |
| Aplazada | Media (5.3) | 0.53% | — | WP Genealogy Developers WP GenealogyAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Black and White WP Genealogy – Your Family History Website wpgenealogy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Genealogy – Your Family History Website: from n/a through <= 0.1.9. | |
| Aplazada | Media (6.5) | 0.40% | — | Best WP Developer BWD Elementor AddonsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer BWD Elementor Addons bwd-elementor-addons allows DOM-Based XSS.This issue affects BWD Elementor Addons: from n/a through <= 4.4.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Yazamodeveloper LeadquizzesAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yazamodeveloper LeadQuizzes leadquizzes allows Stored XSS.This issue affects LeadQuizzes: from n/a through <= 1.1.0. | |
| Analizada | Crítica (9.8) | 0.78% | — | Aliconnect Software Development KIT | 28/3/2025 | 17/6/2026 | A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component. | |
| Aplazada | Alta (7.1) | 0.14% | — | Wpdeveloper Secret MetaAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Secret Meta facebook-secret-meta allows Reflected XSS.This issue affects Secret Meta: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.21% | — | GBS Developer WP Ride BookingAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in GBS Developer WP Ride Booking wp-ride-booking allows Cross Site Request Forgery.This issue affects WP Ride Booking: from n/a through <= 2.4. | |
| Modificada | Media (5.7) | 0.27% | 💥 PoC | Amazon AWS Cloud Development KIT | 21/3/2025 | 17/6/2026 | When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and… | |
| Analizada | Alta (8.8) | 0.45% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (8.8) | 0.44% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (8.8) | 0.44% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Media (6.5) | 0.49% | — | Zoom Meeting Software Development KITZoom Workplace | 11/3/2025 | 17/6/2026 | Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.25% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access. | |
| Analizada | Media (5.4) | 0.22% | — | Wpdeveloper Essential Blocks | 8/3/2025 | 17/6/2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (8.4) | 5.5% | — | National Instruments G WEB Development SoftwareAI | 6/3/2025 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in NI G Web Development Software that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects G Web Development Software 2022 Q3 and prior versions. | |
| Analizada | Media (6.5) | 0.24% | — | Mediatek Software Development KITOpenwrt | 3/3/2025 | 17/6/2026 | In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184. | |
| Analizada | Crítica (9.8) | 0.88% | — | Mediatek Software Development KIT | 3/3/2025 | 17/6/2026 | In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389074; Issue ID: MSV-1803. |