Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.76% | — | Microsoft Purview | 18/7/2025 | 17/6/2026 | Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.4) | 0.25% | — | Affiliate ReviewsAI | 16/7/2025 | 17/6/2026 | The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Baja (2.1) | 0.76% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Baja (2.1) | 0.49% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.60% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url leads to path traversal. The attack can be launched… | |
| Analizada | Baja (2.1) | 0.52% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.1) | 0.21% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious… | |
| Analizada | Alta (8.7) | 0.57% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not sanitized, allowing an attacker to perform SQL injection and… | |
| Analizada | Alta (7.1) | 0.32% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a command without proper sanitization, allowing arbitrary arguments to be… | |
| Analizada | Alta (8.7) | 6.1% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to… | |
| Analizada | Media (5.1) | 0.21% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities. | |
| Analizada | Alta (8.7) | 0.57% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not properly sanitized, allowing an attacker to perform SQL… | |
| Aplazada | Alta (7.1) | 0.31% | — | Advantech IviewAI | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper sanitization, allowing arbitrary arguments to be… | |
| Analizada | Alta (7.2) | 0.29% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition. | |
| Analizada | Media (5.3) | 4.7% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allowing an attacker to… | |
| Analizada | Media (5.1) | 0.21% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other… | |
| Analizada | Media (5.3) | 0.30% | — | Config Pages Viewer Project Config Pages Viewer | 8/7/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4. | |
| Analizada | Media (5.5) | 0.26% | — | Adobe Substance 3D Viewer | 8/7/2025 | 17/6/2026 | Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.23% | — | Adobe Substance 3D Viewer | 8/7/2025 | 17/6/2026 | Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a… | |
| Analizada | Alta (7.8) | 0.24% | — | Adobe Substance 3D Viewer | 8/7/2025 | 17/6/2026 | Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user, scope unchanged. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (8.8) | 0.81% | — | Radiustheme Widget FOR Google Reviews | 8/7/2025 | 17/6/2026 | The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the… | |
| Aplazada | Crítica (9.8) | 0.48% | — | HashviewAI | 7/7/2025 | 17/6/2026 | Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | |
| Aplazada | Alta (8.7) | 0.30% | — | HPE Oneview FOR Vmware VcenterAI | 26/6/2025 | 17/6/2026 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions). | |
| Analizada | Media (5.4) | 0.19% | — | Bourgesloic Post Rating AND Review | 26/6/2025 | 17/6/2026 | The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7) | 0.17% | — | Teamviewer RemoteAITeamviewer TensorAI | 24/6/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only… |