Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.89% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 12/8/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analizada | Alta (8) | 7.7% | 💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 6/8/2025 | 17/6/2026 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security… | |
| Modificada | Media (6.5) | 0.53% | — | Pdf-xchange Editor | 5/8/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. | |
| Modificada | Media (6.5) | 0.53% | — | Pdf-xchange Editor | 5/8/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. | |
| Aplazada | Media (5.5) | 0.83% | — | Kingdee Cloud Starry SKY Enterprise EditionAI | 4/8/2025 | 17/6/2026 | A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file… | |
| Aplazada | Alta (8.1) | 0.36% | — | Opennebula Community EditionAIOpennebula Enterprise EditionAI | 3/8/2025 | 17/6/2026 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their… | |
| Aplazada | Crítica (9.1) | 0.57% | — | Saurus CMS Community EditionAI | 1/8/2025 | 17/6/2026 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowing attackers to… | |
| Modificada | Alta (7.8) | 0.18% | — | Autodesk Infrastructure Parts EditorAutodesk InventorAutodesk Navisworks ManageAutodesk Navisworks Simulate+2 | 24/7/2025 | 17/6/2026 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized. | |
| Aplazada | Media (4.3) | 0.18% | — | Ithoughts Advanced Code EditorAI | 24/7/2025 | 17/6/2026 | The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on the 'ithoughts_ace_update_options' AJAX action. This makes it possible for unauthenticated attackers to update plugin… | |
| Analizada | Crítica (9.8) | 3.3% | 💥 Exploit | Scribu Front-end Editor | 19/7/2025 | 16/6/2026 | The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible. | |
| Aplazada | Media (4.3) | 0.24% | — | Block Editor Gallery SliderAI | 18/7/2025 | 17/6/2026 | The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the classic_gallery_slider_options() function in all versions up to, and including, 1.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (7.1) | 0.21% | — | Arisoft Contact Form 7 Editor ButtonAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft Contact Form 7 Editor Button cf7-editor-button allows Reflected XSS.This issue affects Contact Form 7 Editor Button: from n/a through <= 1.0.0. | |
| Aplazada | Alta (8.5) | 0.36% | — | Elextensions Elex Woocommerce Advanced Bulk Edit Products Prices AttributesAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes elex-bulk-edit-products-prices-attributes-for-woocommerce-basic allows SQL Injection.This issue affects ELEX WooCommerce Advanced Bulk… | |
| Aplazada | Baja (2.3) | 0.22% | — | Jiransoft Crosseditor4AI | 15/7/2025 | 17/6/2026 | The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23. | |
| Analizada | Baja (2.1) | 0.76% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Baja (2.1) | 0.49% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.60% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url leads to path traversal. The attack can be launched… | |
| Analizada | Baja (2.1) | 0.52% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (4.8) | 0.31% | — | Asustor ADMAIAsustor Text EditorAI | 14/7/2025 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other sensitive information retained by the browser and used with the… | |
| Analizada | Media (5.6) | 0.28% | — | Malvineous Masseditregex | 3/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before… | |
| Aplazada | Media (6.5) | 0.23% | — | Aviplugins Thumbnail EditorAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Thumbnail Editor thumbnail-editor allows Stored XSS.This issue affects Thumbnail Editor: from n/a through <= 2.3.3. | |
| Aplazada | Media (5.9) | 0.26% | — | Josh WP EditAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh WP Edit wp-edit allows Stored XSS.This issue affects WP Edit: from n/a through <= 4.0.4. | |
| Aplazada | Media (5.3) | 0.36% | — | Roland Audio Editor RecorderAI | 27/6/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Retrieve Embedded Sensitive Data.This issue affects Audio Editor & Recorder: from n/a through <= 2.2.3. | |
| Aplazada | Media (5.5) | 0.43% | — | Kingdee Cloud-starry-sky Enterprise EditionAIApache FreemarkerAI | 27/6/2025 | 17/6/2026 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of the file \k3\o2o\bos\webapp\action\DynamicForm 4 Action.class of the component Freemarker Engine. The manipulation leads to… |