Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.27% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Baja (3.3) | 0.26% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.29% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.29% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Baja (3.3) | 0.24% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.27% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Baja (3.3) | 0.24% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.29% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 25/6/2025 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Baja (2.1) | 0.52% | — | Scriptandtools Real Estate Management System | 20/6/2025 | 17/6/2026 | A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated… | |
| Analizada | Baja (1.9) | 0.26% | — | Swftools | 19/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Idrac Tools | 12/6/2025 | 17/6/2026 | Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (4.8) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface`… | |
| Analizada | Media (5.4) | 0.42% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the… | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the… | |
| Analizada | Crítica (9.1) | 42% | 💥 Exploit | GeotoolsOsgeo GeonetworkOsgeo Geoserver | 10/6/2025 | 17/6/2026 | GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the… | |
| Aplazada | Media (4.3) | 0.16% | — | Billminozzi WP ToolsAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Cross Site Request Forgery.This issue affects WP Tools: from n/a through <= 5.24. | |
| Analizada | Media (6.9) | 0.60% | — | Scriptandtools Real Estate Management System | 24/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Alta (7.1) | 0.27% | — | B2itech B2I Investor ToolsAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in B2itech B2i Investor Tools b2i-investor-tools allows Reflected XSS.This issue affects B2i Investor Tools: from n/a through <= 1.0.7.9. | |
| Aplazada | Media (6.1) | 0.34% | — | Affiliate Sales IN Google Analytics AND Other ToolsAI | 21/5/2025 | 17/6/2026 | The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This makes it possible for unauthenticated attackers to redirect… | |
| Aplazada | Media (6.8) | 0.24% | — | Vmware EsxiAIVmware Vcenter ServerAIVmware ToolsAI | 20/5/2025 | 17/6/2026 | VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools… | |
| Analizada | Alta (7.7) | 1.5% | 💥 PoC | Python SetuptoolsDebian Linux | 17/5/2025 | 17/6/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of… | |
| Analizada | Media (5.4) | 0.30% | — | Toolstack Cyan Backup | 15/5/2025 | 17/6/2026 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.30% | — | Toolstack Cyan Backup | 15/5/2025 | 17/6/2026 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |