Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.21%—Intel Tiber Edge PlatformAIIntel Edge OrchestratorAI12/8/202517/6/2026
Protection mechanism failure for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.
AplazadaAlta (7.5)0.58%—UI Edgemax EdgeswitchAI4/8/202517/6/2026
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent network.
AplazadaMedia (6.4)0.23%—Magic Edge LiteAI2/8/202517/6/2026
The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaAlta (8.9)0.77%—Lfedge Ekuiper24/7/202517/6/2026
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute…
AplazadaMedia (4.4)0.26%💥 PoCKnowledge BaseAI18/7/202517/6/2026
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject…
ModificadaMedia (4.3)0.45%—Microsoft Edge Chromium11/7/202517/6/2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
ModificadaMedia (6.5)0.56%—Microsoft Edge Chromium11/7/202517/6/2026
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.6)0.34%—Microsoft Edge Chromium11/7/202517/6/2026
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (7.3)0.16%—Siemens Solid Edge8/7/202517/6/2026
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted CFG files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.15%—Siemens Solid Edge8/7/202517/6/2026
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.15%—Siemens Solid Edge8/7/202517/6/2026
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
AplazadaCrítica (9.8)0.36%—Clickandpledge Click AND Pledge ConnectAI4/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.
AnalizadaAlta (8.8)0.81%—Microsoft Edge Chromium2/7/202517/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.5)3.9%💥 ExploitMicrosoft Edge Chromium1/7/202517/6/2026
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.8)0.72%—Mmz-001 Knowledgegpt24/6/202517/6/2026
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.
AplazadaAlta (7.1)0.13%—Devfelixmoira Knowledge Base MakerAI20/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8.
AplazadaCrítica (9.3)0.43%—Clickandpledge Click Pledge WpjobboardAI10/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge WordPress-WPJobBoard click-pledge-wpjobboard allows Blind SQL Injection.This issue affects WordPress-WPJobBoard: from n/a through <= 25.07010000-WP6.8.1-JB5.11.5.
AplazadaMedia (6.4)0.22%—Knowledge BaseAI6/6/202517/6/2026
The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)7.8%⚠ Explotación activa💥 PoCGoogle ChromeMicrosoft Edge Chromium3/6/202517/6/2026
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AplazadaAlta (8.8)0.44%—Openknowledgemaps HeadstartAI29/5/202517/6/2026
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component
AnalizadaAlta (8.8)0.58%💥 PoCMicrosoft Edge Update22/5/202517/6/2026
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.4)0.29%—Lfedge Ekuiper14/5/202517/6/2026
LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Configuration key `Name` (`confKey`) parameter. After this setup,…
AplazadaMedia (5.1)0.21%—Intel Tiber Edge PlatformAI13/5/202517/6/2026
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
AplazadaMedia (6)0.18%—Intel Tiber Edge PlatformAI13/5/202517/6/2026
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via local access.
AplazadaMedia (5.1)0.22%—Intel Tiber Edge PlatformAIIntel Edge OrchestratorAI13/5/202517/6/2026
Improper conditions check for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.