Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.49% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the… | |
| Analizada | Crítica (9.3) | 0.73% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for… | |
| Analizada | Crítica (9.3) | 0.67% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation… | |
| Analizada | Alta (8.8) | 0.53% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for… | |
| Modificada | Alta (7.5) | 0.51% | — | Kiloview E3 Firmware | 6/11/2025 | 5/7/2026 | An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component. | |
| Aplazada | Alta (7.1) | 0.24% | — | Jegtheme Epic ReviewAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme Epic Review epic-review allows Reflected XSS.This issue affects Epic Review: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.4) | 0.24% | — | Bootstrapped Visual Link PreviewAI | 5/11/2025 | 17/6/2026 | The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.26% | — | Repuso Social Proof Testimonials AND ReviewsAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 5.29. | |
| Aplazada | Media (6.5) | 0.31% | — | Wikimedia Wikipedia PreviewAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Wikimedia Foundation Wikipedia Preview wikipedia-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wikipedia Preview: from n/a through <= 1.15.0. | |
| Aplazada | Alta (7.5) | 0.49% | — | Crocoblock JetreviewsAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-reviews allows PHP Local File Inclusion.This issue affects JetReviews: from n/a through <= 3.0.0. | |
| Aplazada | Media (5.3) | 0.34% | — | Wpclever WPC Smart Quick ViewAI | 18/10/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data… | |
| Aplazada | Media (6.4) | 0.24% | — | WP ViewstlAI | 15/10/2025 | 17/6/2026 | The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.5) | 0.17% | — | Remoteview PC Application ConsoleAI | 15/10/2025 | 17/6/2026 | RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Analizada | Alta (7.8) | 0.19% | — | Adobe Substance 3D Viewer | 14/10/2025 | 17/6/2026 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.16% | — | Adobe Substance 3D Viewer | 14/10/2025 | 17/6/2026 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to crash the application or make it unavailable. Exploitation of this issue requires user interaction in that a victim… | |
| Analizada | Alta (7.8) | 0.24% | — | Adobe Substance 3D Viewer | 14/10/2025 | 17/6/2026 | Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.19% | — | Adobe Substance 3D Viewer | 14/10/2025 | 17/6/2026 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (8.7) | 0.46% | — | Rockwellautomation Factorytalk ViewpointAI | 14/10/2025 | 17/6/2026 | A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service. | |
| Analizada | Alta (8.7) | 0.61% | — | Rockwellautomation Factorytalk View | 14/10/2025 | 17/6/2026 | A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted. | |
| Analizada | Alta (7) | 0.39% | — | Rockwellautomation Factorytalk View | 14/10/2025 | 17/6/2026 | An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more. | |
| Aplazada | Crítica (10) | 0.24% | — | Kiloview NDI N30AI | 13/10/2025 | 17/6/2026 | A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246 | |
| Aplazada | Alta (8.7) | 0.20% | — | Kiloview N30AI | 13/10/2025 | 17/6/2026 | Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the network | |
| Aplazada | Media (4.9) | 0.71% | — | Bestwebsoft Error LOG ViewerAI | 11/10/2025 | 17/6/2026 | The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the… | |
| Aplazada | Alta (8.4) | 0.16% | — | Denso TEN Drive Recorder ViewerAI | 6/10/2025 | 17/6/2026 | The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer. | |
| Aplazada | Alta (7.8) | 0.15% | — | Nvidia Installer FOR Nvapp FOR WindowsAINvidia Frameview SDKAI | 1/10/2025 | 17/6/2026 | NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of privileges. |