Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.89%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.4%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalizadaAlta (8)7.7%💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition6/8/202517/6/2026
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security…
ModificadaMedia (6.5)0.53%—Pdf-xchange Editor5/8/202517/6/2026
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
ModificadaMedia (6.5)0.53%—Pdf-xchange Editor5/8/202517/6/2026
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
AplazadaMedia (5.5)0.83%—Kingdee Cloud Starry SKY Enterprise EditionAI4/8/202517/6/2026
A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file…
AplazadaAlta (8.1)0.36%—Opennebula Community EditionAIOpennebula Enterprise EditionAI3/8/202517/6/2026
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their…
AplazadaCrítica (9.1)0.57%—Saurus CMS Community EditionAI1/8/202517/6/2026
Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to…
ModificadaAlta (7.8)0.18%—Autodesk Infrastructure Parts EditorAutodesk InventorAutodesk Navisworks ManageAutodesk Navisworks Simulate+224/7/202517/6/2026
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
AplazadaMedia (4.3)0.18%—Ithoughts Advanced Code EditorAI24/7/202517/6/2026
The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on the 'ithoughts_ace_update_options' AJAX action. This makes it possible for unauthenticated attackers to update plugin…
AnalizadaCrítica (9.8)3.3%💥 ExploitScribu Front-end Editor19/7/202516/6/2026
The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
AplazadaMedia (4.3)0.24%—Block Editor Gallery SliderAI18/7/202517/6/2026
The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the classic_gallery_slider_options() function in all versions up to, and including, 1.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (7.1)0.21%—Arisoft Contact Form 7 Editor ButtonAI16/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft Contact Form 7 Editor Button cf7-editor-button allows Reflected XSS.This issue affects Contact Form 7 Editor Button: from n/a through <= 1.0.0.
AplazadaAlta (8.5)0.36%—Elextensions Elex Woocommerce Advanced Bulk Edit Products Prices AttributesAI16/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes elex-bulk-edit-products-prices-attributes-for-woocommerce-basic allows SQL Injection.This issue affects ELEX WooCommerce Advanced Bulk…
AplazadaBaja (2.3)0.22%—Jiransoft Crosseditor4AI15/7/202517/6/2026
The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.
AnalizadaBaja (2.1)0.76%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack…
AnalizadaBaja (2.1)0.49%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The…
AnalizadaBaja (2.1)0.60%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url leads to path traversal. The attack can be launched…
AnalizadaBaja (2.1)0.52%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The…
AplazadaMedia (4.8)0.31%—Asustor ADMAIAsustor Text EditorAI14/7/202517/6/2026
A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other sensitive information retained by the browser and used with the…
AnalizadaMedia (5.6)0.28%—Malvineous Masseditregex3/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before…
AplazadaMedia (6.5)0.23%—Aviplugins Thumbnail EditorAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Thumbnail Editor thumbnail-editor allows Stored XSS.This issue affects Thumbnail Editor: from n/a through <= 2.3.3.
AplazadaMedia (5.9)0.26%—Josh WP EditAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh WP Edit wp-edit allows Stored XSS.This issue affects WP Edit: from n/a through <= 4.0.4.
AplazadaMedia (5.3)0.36%—Roland Audio Editor RecorderAI27/6/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Retrieve Embedded Sensitive Data.This issue affects Audio Editor & Recorder: from n/a through <= 2.2.3.
AplazadaMedia (5.5)0.43%—Kingdee Cloud-starry-sky Enterprise EditionAIApache FreemarkerAI27/6/202517/6/2026
A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of the file \k3\o2o\bos\webapp\action\DynamicForm 4 Action.class of the component Freemarker Engine. The manipulation leads to…