Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Ninguna (0) | 0.44% | — | Wikimedia VectorAI | 2/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Vector. This vulnerability is associated with program files resources/skins.Vector.Js/portlets.Js, resources/skins.Vector.Legacy.Js/portlets.Js. This issue affects Vector: from >= 1.40.0… | |
| Aplazada | Ninguna (0) | 0.32% | — | Wikimedia MultimediaviewerAI | 2/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0. | |
| Aplazada | Ninguna (0) | 0.32% | — | Wikimedia MediawikiAI | 2/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandbox.Js. This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7… | |
| Aplazada | Baja (2.1) | 0.45% | — | Wikimedia MediawikiAI | 2/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/user/User.Php. This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0. | |
| Aplazada | Baja (2.1) | 0.41% | — | Wikimedia AbusefilterAI | 2/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0. | |
| Aplazada | Ninguna (0) | 0.45% | — | Wikimedia MediawikiAI | 2/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiFeedContributions.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7 1.43.2, 1.44.0. | |
| Aplazada | Media (4.6) | 0.37% | — | Wikimedia MediawikiAI | 2/2/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php. This issue affects MediaWiki: from * through 1.39.12, 1.42.76 1.43.1, 1.44.0. | |
| Aplazada | Baja (2.1) | 0.49% | — | Wikimedia MediawikiAI | 2/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php. This issue affects MediaWiki: >= 1.42.0. | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00827332;… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738293;… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738313;… | |
| Modificada | Media (6.5) | 0.79% | — | Mediatek Nbiot SDKMediatek Software Development KITOpenwrt | 2/2/2026 | 17/6/2026 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461663 / WCNCR00463309; Issue ID:… | |
| Analizada | Alta (8.8) | 0.30% | — | Mediatek Software Development KITOpenwrt | 2/2/2026 | 17/6/2026 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461651; Issue ID: MSV-4758. | |
| Analizada | Crítica (9.3) | 0.18% | — | Mediatek Nbiot SDK | 2/2/2026 | 17/6/2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905. | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01726634; Issue… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01688495; Issue… | |
| Modificada | Media (6.5) | 0.50% | 💥 PoC | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689248;… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note:… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00693083;… | |
| Modificada | Alta (7.5) | 0.73% | — | Mediatek Nr15 | 2/2/2026 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738310; Issue… | |
| Aplazada | Alta (8.8) | 0.48% | — | Wikimedia MediawikiAIWikimedia DiscussiontoolsAI | 30/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki - DiscussionTools Extension: 1.44, 1.43. | |
| Aplazada | Alta (8.4) | 0.59% | — | Zortam MP3 Media StudioAI | 28/1/2026 | 17/6/2026 | Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code execution. Attackers can craft a malicious text file with shellcode to trigger a structured exception handler (SEH) overwrite and execute arbitrary commands on the target system. | |
| Aplazada | Media (5.3) | 0.29% | — | Vzaar Media ManagementAI | 28/1/2026 | 17/6/2026 | The Vzaar Media Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on the $_SERVER['PHP_SELF'] variable. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.5) | 0.34% | — | Najeebmedia Frontend File ManagerAI | 28/1/2026 | 17/6/2026 | The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share arbitrary uploaded files via email by… | |
| Aplazada | Media (5.3) | 0.38% | — | Liuyueyi Quick-mediaAI | 27/1/2026 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java. This issue affects quick-media: before v1.0. |