Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.32%—Beijing Sogou Technology Development CO LTD Sogou Input IOSAI27/1/202517/6/2026
An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaAlta (7.1)0.34%—Gradle DevelocityAI26/1/202517/6/2026
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not include the projects…
AplazadaAlta (8.3)0.47%—Gradle DevelocityAI26/1/202517/6/2026
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection against brute-force…
AplazadaMedia (6.1)0.32%—Quiz Maker BusinessAIQuiz Maker DeveloperAIQuiz Maker AgencyAI26/1/202517/6/2026
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient input…
AplazadaAlta (7.3)0.55%—Quiz Maker BusinessAIQuiz Maker DeveloperAIQuiz Maker AgencyAI26/1/202517/6/2026
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users to execute an…
AplazadaAlta (7.2)0.47%—Ays-pro Quiz Maker BusinessAIAys-pro Quiz Maker DeveloperAIAys-pro Quiz Maker AgencyAI26/1/202517/6/2026
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and…
AplazadaAlta (7.1)0.37%—Limesquare Lime Developer LoginAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in limesquare Lime Developer Login lime-developer-login allows Reflected XSS.This issue affects Lime Developer Login: from n/a through <= 1.4.0.
ModificadaBaja (1.8)0.33%—Amazon AWS Cloud Development KIT17/1/202517/6/2026
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. However, the current…
AnalizadaAlta (7.5)0.57%—Blackberry QNX Software Development Platform14/1/202517/6/2026
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
AnalizadaAlta (7.5)0.44%—Blackberry QNX Software Development Platform14/1/202517/6/2026
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
AnalizadaCrítica (9.8)0.62%—Blackberry QNX Software Development Platform14/1/202517/6/2026
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.
AnalizadaAlta (7.5)0.37%—Blackberry QNX Software Development Platform14/1/202517/6/2026
Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.
AnalizadaAlta (7.5)0.37%—Blackberry QNX Software Development Platform14/1/202517/6/2026
Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.
AnalizadaMedia (4.8)0.24%—Wpdeveloper Essential Blocks8/1/202517/6/2026
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible…
ModificadaMedia (5.4)0.30%—Wpdeveloper Typing Text7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Typing Text typing-text allows Stored XSS.This issue affects Typing Text: from n/a through <= 1.2.7.
AplazadaMedia (5.9)0.31%—Wpdevelop Email-remindersAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Email Reminders email-reminders allows Stored XSS.This issue affects Email Reminders: from n/a through <= 2.0.5.
AplazadaBaja (3.1)0.34%—Clevelandwebdeveloper SpacerAI7/1/202517/6/2026
The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the motech_spacer_callback() function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view limited setting…
AnalizadaAlta (7.5)0.32%—Linuxfoundation YoctoMediatek Software Development KITGoogle Android6/1/202517/6/2026
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
AnalizadaMedia (4.4)0.09%—Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt6/1/202517/6/2026
In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00389047 / ALPS09136505; Issue ID: MSV-1798.
AnalizadaCrítica (9.8)0.26%—Linuxfoundation YoctoMediatek Software Development KITGoogle Android6/1/202517/6/2026
In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389045 / ALPS09136494; Issue ID: MSV-1796.
AnalizadaAlta (8.1)0.14%—Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt6/1/202517/6/2026
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.
ModificadaAlta (8.8)0.36%—Wpdeveloper Betterlinks2/1/202517/6/2026
Missing Authorization vulnerability in WPDeveloper BetterLinks betterlinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through <= 1.6.0.
ModificadaMedia (5.4)0.26%—Wpdeveloper Essential Addons FOR Elementor31/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.7.
AplazadaAlta (7.8)0.22%—Edgecross Basic Software FOR WindowsAIEdgecross Basic Software FOR DevelopersAI19/12/202417/6/2026
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and…
AplazadaAlta (7.8)0.16%—Edgecross Basic Software FOR WindowsAIEdgecross Basic Software FOR DevelopersAI19/12/202417/6/2026
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or…