Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.39%—Best WP Developer Advanced Blog Post BlockAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer Advanced Blog Post Block advanced-blog-post-block allows Stored XSS.This issue affects Advanced Blog Post Block: from n/a through <= 1.0.4.
ModificadaMedia (4.3)0.48%—Wpdeveloper Reviewx13/12/202417/6/2026
Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.
ModificadaMedia (6.5)0.43%—Wpdeveloper Essential Blocks13/12/202417/6/2026
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.
AplazadaMedia (4.4)0.32%—Wpdeveloper NotificationxAI12/12/202417/6/2026
The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content settings for notifications in all versions up to, and including, 2.9.3 due to…
AnalizadaMedia (4.6)0.22%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
AnalizadaAlta (8.8)0.30%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
AnalizadaMedia (6.2)0.22%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).
AnalizadaMedia (6.5)0.36%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.
AnalizadaMedia (6.5)0.40%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.
AnalizadaMedia (6.5)0.40%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.
AnalizadaAlta (8.8)0.46%—Silabs Z-wave Software Development KIT10/12/202417/6/2026
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
ModificadaAlta (8.8)0.31%—Autodesk FBX Software Development KIT9/12/202417/6/2026
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
ModificadaAlta (8.8)0.58%—Wpdeveloper Essential Blocks9/12/202417/6/2026
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.2.0.
ModificadaAlta (8.8)0.59%—Wpdeveloper Essential Blocks9/12/202417/6/2026
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.2.0.
ModificadaMedia (4.3)0.34%—Wpdeveloper Betterdocs9/12/202417/6/2026
Missing Authorization vulnerability in WPDeveloper BetterDocs betterdocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through <= 2.5.2.
AplazadaMedia (4.3)0.34%—Wpdeveloper Simple 301 RedirectsAI9/12/202417/6/2026
Missing Authorization vulnerability in WPDeveloper Simple 301 Redirects by BetterLinks simple-301-redirects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple 301 Redirects by BetterLinks: from n/a through <= 2.0.7.
ModificadaAlta (8.8)0.40%—Wpdeveloper Essential Blocks9/12/202417/6/2026
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.2.0.
AplazadaMedia (5.3)0.45%—Wpexpertdeveloper WP Private Content PlusAI6/12/202417/6/2026
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles…
AnalizadaMedia (6.5)0.12%—Linuxfoundation YoctoMediatek Software Development KITGoogle AndroidOpenwrt2/12/202417/6/2026
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
AnalizadaAlta (7.5)0.29%—Mediatek Software Development KITGoogle Android2/12/202417/6/2026
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
AnalizadaMedia (5.4)0.37%—Wpdeveloper Embedpress28/11/202417/6/2026
The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘provider_name parameter in all versions up to, and including, 4.1.3 due to insufficient input…
AnalizadaAlta (7.5)0.55%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.47%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+219/11/202417/6/2026
Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.5)0.50%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+319/11/202417/6/2026
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.