Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.2% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables… | |
| Analizada | Media (6.5) | 0.20% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information. | |
| Analizada | Alta (8.8) | 0.30% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to… | |
| Analizada | Media (6.5) | 0.21% | — | Teamviewer Digital Employee Experience | 11/12/2025 | 17/6/2026 | A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to cause a denial of service (application crash) via a crafted command, resulting in service termination. | |
| Aplazada | Media (6.4) | 0.23% | — | Trustindex Widgets FOR Google ReviewsAI | 11/12/2025 | 30/9/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trustindex` shortcode in all versions up to, and including, 13.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.7) | 0.49% | — | Commax WebviewerAI | 9/12/2025 | 17/6/2026 | COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit boundary errors in Commax_WebViewer.ocx to cause buffer overflow conditions and potentially… | |
| Aplazada | Media (5.4) | 0.20% | — | Oleksandr Lysyi Debug LOG ViewerAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Oleksandr Lysyi Debug Log Viewer debug-log-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Log Viewer: from n/a through <= 2.0.3. | |
| Aplazada | Media (6.5) | 0.24% | — | Wpmet WP Ultimate ReviewAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7. | |
| Aplazada | Media (5.4) | 0.25% | — | A3rev Page View CountAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Steve Truman Page View Count page-views-count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page View Count: from n/a through <= 2.9.0. | |
| Aplazada | Alta (7.2) | 0.37% | — | Social Reviews AND RecommendationsAI | 9/12/2025 | 7/10/2026 | The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the 'trim_text' function in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.2) | 0.38% | — | Rich Shortcodes FOR Google ReviewsAI | 6/12/2025 | 17/6/2026 | The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.2) | 0.40% | — | Widgets FOR Google ReviewsAI | 6/12/2025 | 17/6/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 13.2.4 due to insufficient input sanitization and output escaping on Google Reviews data imported by the plugin. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.22% | — | Live CSS PreviewAI | 5/12/2025 | 17/6/2026 | The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_frontend_save' AJAX endpoint in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Alta (8.7) | 0.44% | — | Advantech IviewAI | 4/12/2025 | 17/6/2026 | Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands. | |
| Aplazada | Media (5.3) | 0.26% | — | Quick View FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Aplazada | Media (6.1) | 0.21% | — | Customer Reviews CollectorAI | 27/11/2025 | 17/6/2026 | The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email-text' parameter in all versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.1) | 0.27% | — | Opto22 Groov ViewAI | 26/11/2025 | 17/6/2026 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators. | |
| Modificada | Alta (7.5) | 0.35% | — | Interviewx Echo | 25/11/2025 | 5/7/2026 | An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send email verification messages to arbitrary users via the /sendEmailCodeForResetPwd endpoint potentially causing a denial of service to the server or the downstream users. | |
| Aplazada | Media (5.4) | 0.24% | — | Jgwhite33 WP Google Places Review SliderAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4. | |
| Aplazada | Media (6.4) | 0.18% | — | Shortcode FOR Google Street ViewAI | 21/11/2025 | 17/6/2026 | The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetview' shortcode in all versions up to, and including, 0.5.7. This is due to insufficient input sanitization and output escaping on the 'id' attribute. This makes it possible for authenticated… | |
| Analizada | Baja (2) | 0.38% | — | Janobe Interview Management System | 18/11/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php. The manipulation of the argument Question results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Modificada | Alta (7.5) | 0.48% | 💥 PoC | Simicam IP Camera FirmwareKeview IP Camera FirmwareAsecam IP Camera Firmware | 12/11/2025 | 17/6/2026 | Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication. | |
| Analizada | Baja (2.1) | 0.32% | — | Janobe Interview Management System | 10/11/2025 | 7/10/2026 | A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has been released to the… | |
| Aplazada | Media (4) | 0.22% | — | Ljapps WP Airbnb Review SliderAI | 7/11/2025 | 7/10/2026 | The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2 due to insufficient URL validation that allows users to pull in a malicious HTML file. This makes it possible for authenticated attackers, with administrator-level… | |
| Analizada | Crítica (9.3) | 0.67% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows… |