Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.17% | — | Home-assistant CompanionAIHome-assistant Home AssistantAI | 29/5/2026 | 21/7/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and… | |
| Aplazada | Media (6.5) | 0.22% | — | Toocheke CompanionAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows DOM-Based XSS.This issue affects Toocheke Companion: from n/a through <= 1.194. | |
| Aplazada | Media (4.3) | 0.15% | — | Wpmoose Kenta CompanionAI | 19/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Moose Kenta Companion kenta-companion allows Cross Site Request Forgery.This issue affects Kenta Companion: from n/a through <= 1.3.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Extendthemes Mesmerize CompanionAIExtendthemes MesmerizeAI | 19/2/2026 | 17/6/2026 | The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the "openPageInCustomizer" and "openPageInDefaultEditor" functions in all versions up to, and including, 1.6.158. This makes it possible for authenticated attackers - with… | |
| Aplazada | Alta (8.5) | 0.17% | — | Lavasoft Adaware WEB CompanionAI | 5/2/2026 | 17/6/2026 | Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious… | |
| Aplazada | Alta (8.5) | 0.14% | — | Adaware WEB CompanionAI | 3/2/2026 | 17/6/2026 | Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup. | |
| Aplazada | Media (4.3) | 0.21% | — | Horea Radu Materialis CompanionAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Horea Radu Materialis Companion materialis-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Materialis Companion: from n/a through <= 1.3.52. | |
| Analizada | Alta (8.6) | 0.26% | — | Eaton UPS Companion | 26/12/2025 | 17/6/2026 | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | |
| Analizada | Alta (7.8) | 0.15% | — | Eaton UPS Companion | 26/12/2025 | 6/10/2026 | Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | |
| Analizada | Media (6.7) | 0.19% | — | Eaton UPS Companion | 26/12/2025 | 6/10/2026 | Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | |
| Aplazada | Media (4.3) | 0.13% | — | Codeworkweb CWW CompanionAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codeworkweb CWW Companion cww-companion allows Cross Site Request Forgery.This issue affects CWW Companion: from n/a through <= 1.3.2. | |
| Aplazada | Alta (8.8) | 0.69% | — | Creativethemes Blocksy CompanionAI | 11/11/2025 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to insufficient file type validation detecting SVG files, allowing double extension files to bypass sanitization while being accepted as a valid SVG file. This makes… | |
| Aplazada | Media (6.4) | 0.22% | — | Magazine CompanionAI | 11/11/2025 | 17/6/2026 | The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribute in the bnm-blocks/featured-posts-1 block in all versions up to, and including, 1.2.3. This is due to insufficient input sanitization and output escaping when using user-supplied values as HTML tag… | |
| Aplazada | Media (6.4) | 0.20% | — | Creativethemes Blocksy CompanionAI | 30/10/2025 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.20% | — | Horea Radu ONE Page Express CompanionAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Horea Radu One Page Express Companion one-page-express-companion.This issue affects One Page Express Companion: from n/a through <= 1.6.43. | |
| Aplazada | Alta (7.3) | 0.29% | — | Lavasoft WEB CompanionAI | 9/10/2025 | 17/6/2026 | Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with write access to the file system could potentially execute arbitrary code with elevated privileges by placing a malicious… | |
| Aplazada | Media (6.4) | 0.25% | — | Creativethemes Blocksy CompanionAI | 17/9/2025 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.5) | 0.27% | — | Codeermeneer Companion Auto UpdateAI | 15/7/2025 | 17/6/2026 | The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ parameter in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access,… | |
| Aplazada | Alta (8.8) | 0.18% | — | Infigosoftware Is-theme-companionAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software IS-theme-companion weblizar-companion allows Object Injection.This issue affects IS-theme-companion: from n/a through <= 1.59. | |
| Analizada | Media (5.4) | 0.34% | — | Wpzita Z Companion | 11/4/2025 | 17/6/2026 | The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Aplazada | Media (6.5) | 0.28% | — | Specia CompanionAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Specia Theme Specia Companion specia-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Specia Companion: from n/a through <= 6.3. | |
| Aplazada | Media (5.4) | 0.49% | — | Wpzita Z CompanionAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in wpzita Z Companion z-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Z Companion: from n/a through <= 1.0.13. | |
| Aplazada | Media (5.9) | 0.23% | — | Toocheke CompanionAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows Stored XSS.This issue affects Toocheke Companion: from n/a through <= 1.166. | |
| Analizada | Crítica (9.8) | 54% | 💥 Exploit | Themehunk Hunk Companion | 31/12/2024 | 17/6/2026 | The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Straightvisions Sv100 CompanionAI | 16/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in straightvisions GmbH SV100 Companion sv100-companion allows Privilege Escalation.This issue affects SV100 Companion: from n/a through <= 2.0.02. |