Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.29% | — | Ideabox Creations Powerpack PRO FOR ElementorAI | 23/12/2025 | 17/6/2026 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.6. | |
| Aplazada | Baja (2.3) | 0.18% | — | PowergAI | 22/12/2025 | 17/6/2026 | Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network. | |
| Analizada | Alta (8.7) | 0.36% | — | Powerstonegh Affiliate ME | 17/12/2025 | 17/6/2026 | Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes. | |
| Analizada | Baja (3.3) | 0.14% | — | Sunbirddcim Power IQ | 15/12/2025 | 17/6/2026 | An error-based SQL injection vulnerability exists in the Sunbird Power IQ 9.2.0 API. The vulnerability is due to an outdated API endpoint that applied arrays without proper input validation. This can allow attackers to manipulate SQL queries. This has been addressed in Power IQ version 9.2.1, where the API call code… | |
| Modificada | Baja (2.1) | 0.35% | — | Powerjob | 11/12/2025 | 17/6/2026 | A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request… | |
| Modificada | Media (4.3) | 0.28% | — | Qodeinteractive Powerlift | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from n/a through < 3.2.1. | |
| Analizada | Alta (7.5) | 0.58% | — | Powerdns Recursor | 9/12/2025 | 7/10/2026 | An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. | |
| Analizada | Media (5.3) | 0.37% | — | Powerdns Recursor | 9/12/2025 | 7/10/2026 | An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY. | |
| Aplazada | Alta (8.8) | 0.60% | — | Blubrry PowerpressAI | 27/11/2025 | 17/6/2026 | The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. This… | |
| Modificada | Alta (7.7) | 0.32% | — | Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+25 | 26/11/2025 | 31/8/2026 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,… | |
| Aplazada | Baja (1) | 0.12% | — | Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI | 23/11/2025 | 17/6/2026 | The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in… | |
| Aplazada | Media (5.6) | 0.11% | — | Schneider-electric Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain administrative application privileges. | |
| Aplazada | Alta (8.7) | 0.39% | — | Schneider-electric Spectrum PowerAI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user. | |
| Aplazada | Alta (8.5) | 0.12% | — | Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands… | |
| Aplazada | Alta (8.5) | 0.11% | — | CA Spectrum PowerAI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attacker to gain administrative privileges. | |
| Aplazada | Alta (8.5) | 0.12% | — | Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local user to gain code execution as administrative application user. | |
| Analizada | Alta (8.1) | 0.79% | — | Microsoft Nuance Powerscribe 360Microsoft Nuance Powerscribe ONE | 11/11/2025 | 29/6/2026 | Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.18% | — | Dell Powerscale Onefs | 10/11/2025 | 7/10/2026 | Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (6.1) | 0.22% | — | Remyandrade Ai-powered To-do List APP | 7/11/2025 | 17/6/2026 | Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Add Task"… | |
| Aplazada | Media (4.3) | 0.13% | — | Blubrry PowerpressAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12. | |
| Aplazada | Media (5.3) | 0.47% | — | Powerbi Embed ReportsAI | 18/10/2025 | 17/6/2026 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hooked on 'init'. This… | |
| Aplazada | Media (6.8) | 0.12% | — | Lenovo Power Management DriverAI | 15/10/2025 | 17/6/2026 | A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.3) | 0.48% | — | Microsoft PowershellMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+13 | 14/10/2025 | 17/6/2026 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |
| Modificada | Media (5.5) | 0.46% | — | Powerjob | 10/10/2025 | 17/6/2026 | A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |