Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
1970 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.43% | — | Pab1it0 Azure Data Explorer MCP Server | 27/3/2026 | 17/6/2026 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP… | |
| Analizada | Alta (8.6) | 0.22% | — | Rttsoftware PDF Explorer | 26/3/2026 | 17/6/2026 | PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields… | |
| Analizada | Media (5.7) | 0.15% | — | Jetbrains Datalore | 13/3/2026 | 17/6/2026 | In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings | |
| Aplazada | Media (6.9) | 0.13% | — | Spotie Internet Explorer Password RecoveryAI | 11/3/2026 | 17/6/2026 | SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a… | |
| Analizada | Crítica (9.3) | 0.96% | — | Xiaomi Fileexplorer | 11/3/2026 | 14/7/2026 | MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows… | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.00% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.72% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.70% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.23% | — | Alex4ssb ADB Explorer | 25/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the ADB binary to be executed, to be set to a Universal Naming Convention (UNC) path in the application's settings file. This allows an attacker… | |
| Analizada | Alta (7.1) | 0.23% | — | Alex4ssb ADB Explorer | 20/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a custom data directory, but only check… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themeex Lorem Ipsum Books Media StoreAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11. | |
| Aplazada | Alta (7.8) | 0.20% | — | Alex4ssb ADB ExplorerAI | 20/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authenticity of the ADB binary path specified in the ManualAdbPath setting before executing it, allowing arbitrary code execution with the privileges of the current user. An attacker can exploit this by… | |
| Aplazada | Alta (7.8) | 0.67% | — | Newtonsoft JsonAIAlex4ssb ADB ExplorerAI | 13/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to… | |
| Analizada | Media (6.7) | 0.20% | — | Nsasoft Product KEY Explorer | 12/2/2026 | 17/6/2026 | Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow when pasted into the registration name… | |
| Modificada | Media (6.5) | 0.54% | — | Microsoft Azure IOT Explorer | 10/2/2026 | 17/6/2026 | Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.4) | 0.38% | — | 10-strike Network Inventory ExplorerAI | 5/2/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code… | |
| Aplazada | Alta (8.4) | 0.71% | — | 10-strike Network Inventory ExplorerAI | 5/2/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution… | |
| Analizada | Media (6.7) | 0.27% | — | Nsasoft Product KEY Explorer | 5/2/2026 | 29/6/2026 | Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the… | |
| Aplazada | Media (4.9) | 0.47% | — | Bowo Code ExplorerAI | 4/2/2026 | 17/6/2026 | The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via the 'file' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Alta (8.4) | 0.54% | — | 10-strike Network Inventory ExplorerAI | 28/1/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code execution. | |
| Analizada | Alta (7.4) | 0.60% | — | Microsoft Azure Data Explorer | 22/1/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (7.1) | 0.27% | — | Dmytro Shteflyuk CodecolorerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmytro Shteflyuk CodeColorer codecolorer allows Stored XSS.This issue affects CodeColorer: from n/a through <= 0.10.1. | |
| Aplazada | Alta (8.5) | 0.15% | — | Fspro Event LOG ExplorerAI | 21/1/2026 | 17/6/2026 | Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations that will be executed with… | |
| Aplazada | Media (5.1) | 0.36% | — | Markdown ExplorerAI | 16/1/2026 | 17/6/2026 | Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads that execute in the application's privileged renderer context, allowing code execution on… |