Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.29%—Ideabox Creations Powerpack PRO FOR ElementorAI23/12/202517/6/2026
Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.6.
AplazadaBaja (2.3)0.18%—PowergAI22/12/202517/6/2026
Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.
AnalizadaAlta (8.7)0.36%—Powerstonegh Affiliate ME17/12/202517/6/2026
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.
AnalizadaBaja (3.3)0.14%—Sunbirddcim Power IQ15/12/202517/6/2026
An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outdated API endpoint that applied arrays without proper input validation. This can allow attackers to manipulate SQL queries. This has been addressed in Power IQ version 9.2.1, where the API call code…
ModificadaBaja (2.1)0.35%—Powerjob11/12/202517/6/2026
A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request…
ModificadaMedia (4.3)0.28%—Qodeinteractive Powerlift9/12/20257/10/2026
Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from n/a through < 3.2.1.
AnalizadaAlta (7.5)0.58%—Powerdns Recursor9/12/20257/10/2026
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
AnalizadaMedia (5.3)0.37%—Powerdns Recursor9/12/20257/10/2026
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
AplazadaAlta (8.8)0.60%—Blubrry PowerpressAI27/11/202517/6/2026
The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. This…
ModificadaAlta (7.7)0.32%—Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+2526/11/202531/8/2026
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,…
AplazadaBaja (1)0.12%—Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI23/11/202517/6/2026
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in…
AplazadaMedia (5.6)0.11%—Schneider-electric Spectrum Power 4AI11/11/202526/9/2026
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain administrative application privileges.
AplazadaAlta (8.7)0.39%—Schneider-electric Spectrum PowerAI11/11/202526/9/2026
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.
AplazadaAlta (8.5)0.12%—Spectrum Power 4AI11/11/202526/9/2026
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands…
AplazadaAlta (8.5)0.11%—CA Spectrum PowerAI11/11/202526/9/2026
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attacker to gain administrative privileges.
AplazadaAlta (8.5)0.12%—Spectrum Power 4AI11/11/202526/9/2026
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user.
AnalizadaAlta (8.1)0.79%—Microsoft Nuance Powerscribe 360Microsoft Nuance Powerscribe ONE11/11/202529/6/2026
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.18%—Dell Powerscale Onefs10/11/20257/10/2026
Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaMedia (6.1)0.22%—Remyandrade Ai-powered To-do List APP7/11/202517/6/2026
Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Add Task"…
AplazadaMedia (4.3)0.13%—Blubrry PowerpressAI29/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
AplazadaMedia (5.3)0.47%—Powerbi Embed ReportsAI18/10/202517/6/2026
The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hooked on 'init'. This…
AplazadaMedia (6.8)0.12%—Lenovo Power Management DriverAI15/10/202517/6/2026
A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error.
AnalizadaAlta (7.8)0.38%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint14/10/202517/6/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.3)0.48%—Microsoft PowershellMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+1314/10/202517/6/2026
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
ModificadaMedia (5.5)0.46%—Powerjob10/10/202517/6/2026
A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.