Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.
AplazadaAlta (7.2)0.70%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.
AplazadaAlta (7.2)0.54%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.
AplazadaAlta (8.8)0.42%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.
AplazadaMedia (6.5)0.37%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.
AplazadaMedia (6.5)0.34%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.
AplazadaMedia (6.5)0.41%—Geovision Gv-lpc2211AI10/9/202610/9/2026
GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.
Pendiente de análisisMedia (4.3)0.22%—Gnome GvfsAI1/9/20262/9/2026
A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted…
Pendiente de análisisMedia (6.5)0.45%—Gnome GvfsAI1/9/20264/9/2026
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the…
Pendiente de análisisMedia (4.3)0.37%—Gnome GvfsAI1/9/20262/9/2026
A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the…
Pendiente de análisisAlta (8.8)0.36%—Gnome GvfsAI1/9/20261/10/2026
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to…
AplazadaAlta (7.5)0.55%—Gvectors WpforoAI28/8/202628/8/2026
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
AplazadaAlta (8.1)0.23%—Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI26/8/202626/8/2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,…
AplazadaAlta (8.8)0.62%—Pingvin Share XAI12/8/20269/9/2026
Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchronous…
AplazadaAlta (7.3)0.19%—Geovision Gv-asmanagerAI4/8/20269/9/2026
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed…
AplazadaMedia (4.3)0.25%—Gvectors WpforoAI4/8/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned…
AplazadaMedia (5.4)0.23%—Gvectors WpforoAI1/8/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile,…
AplazadaMedia (5.4)0.29%—Gvectors Wpforo ForumAI31/7/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.
AnalizadaAlta (8.8)0.60%—Pgvector Project Pgvector29/7/202620/8/2026
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
AplazadaAlta (7.3)0.17%—Geovision Gv-ip Device UtilityAI24/7/202630/7/2026
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.
AplazadaMedia (6.4)0.36%—Gvectors WpforoAI16/7/202616/7/2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
AplazadaCrítica (9.3)0.70%—PgvectorAIApache CassandraAIPraisonaiAI11/7/202614/7/2026
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated…
Pendiente de análisisAlta (7.6)0.47%—Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI10/7/202613/7/2026
LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without…
AplazadaMedia (4.3)0.35%—Dsgvo ALL IN ONEAI9/7/20269/7/2026
The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plugin options. This…