Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.37% | — | Cogview4AIHuggingface DiffusersAI | 23/12/2025 | 17/6/2026 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Modificada | Alta (7.2) | 1.0% | — | Microsoft Purview | 18/12/2025 | 17/6/2026 | '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 17/6/2026 | There is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 17/6/2026 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 17/6/2026 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 17/6/2026 | There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 17/6/2026 | There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 17/6/2026 | There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 30/9/2026 | There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 30/9/2026 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This… | |
| Analizada | Alta (8.5) | 0.16% | — | NI Labview | 18/12/2025 | 30/9/2026 | There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This… | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | HPE Oneview | 16/12/2025 | 17/6/2026 | A remote code execution issue exists in HPE OneView. | |
| Aplazada | Media (5.3) | 0.25% | — | Etruel WP Views CounterAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in etruel WP Views Counter wpecounter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Views Counter: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.4) | 0.29% | — | Yithemes Yith Woocommerce Quick ViewAI | 13/12/2025 | 7/10/2026 | The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_quick_view shortcode in all versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.50% | — | Wp3d Model Import ViewerAI | 13/12/2025 | 7/10/2026 | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary… | |
| Aplazada | Media (6.4) | 0.35% | — | Reviews SortedAI | 12/12/2025 | 7/10/2026 | The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [reviews-slider] shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.7) | 0.17% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchange-NomadClientHealth-ConfigureGeneralSetting instruction prior V3.4. Improper protection of the execution path on the local device allows attackers, with local access to the device during execution,… | |
| Analizada | Media (6.7) | 0.18% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 0.87% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated… | |
| Analizada | Alta (7.2) | 0.83% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-LogoffUser instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote… | |
| Analizada | Alta (7.2) | 1.1% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndHash instruction prior V21.1. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables… | |
| Analizada | Alta (7.2) | 1.2% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… | |
| Analizada | Alta (7.2) | 1.2% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of… |