Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

1970 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.43%—Pab1it0 Azure Data Explorer MCP Server27/3/202617/6/2026
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP…
AnalizadaAlta (8.6)0.22%—Rttsoftware PDF Explorer26/3/202617/6/2026
PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields…
AnalizadaMedia (5.7)0.15%—Jetbrains Datalore13/3/202617/6/2026
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
AplazadaMedia (6.9)0.13%—Spotie Internet Explorer Password RecoveryAI11/3/202617/6/2026
SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a…
AnalizadaCrítica (9.3)0.96%—Xiaomi Fileexplorer11/3/202614/7/2026
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows…
AnalizadaAlta (7.5)1.0%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.00%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.72%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.70%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.23%—Alex4ssb ADB Explorer25/2/202617/6/2026
ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the ADB binary to be executed, to be set to a Universal Naming Convention (UNC) path in the application's settings file. This allows an attacker…
AnalizadaAlta (7.1)0.23%—Alex4ssb ADB Explorer20/2/202617/6/2026
ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a custom data directory, but only check…
AplazadaCrítica (9.8)0.39%—Themeex Lorem Ipsum Books Media StoreAI20/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11.
AplazadaAlta (7.8)0.20%—Alex4ssb ADB ExplorerAI20/2/202617/6/2026
ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authenticity of the ADB binary path specified in the ManualAdbPath setting before executing it, allowing arbitrary code execution with the privileges of the current user. An attacker can exploit this by…
AplazadaAlta (7.8)0.67%—Newtonsoft JsonAIAlex4ssb ADB ExplorerAI13/2/202617/6/2026
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to…
AnalizadaMedia (6.7)0.20%—Nsasoft Product KEY Explorer12/2/202617/6/2026
Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow when pasted into the registration name…
ModificadaMedia (6.5)0.54%—Microsoft Azure IOT Explorer10/2/202617/6/2026
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AplazadaAlta (8.4)0.38%—10-strike Network Inventory ExplorerAI5/2/202617/6/2026
10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code…
AplazadaAlta (8.4)0.71%—10-strike Network Inventory ExplorerAI5/2/202617/6/2026
10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution…
AnalizadaMedia (6.7)0.27%—Nsasoft Product KEY Explorer5/2/202629/6/2026
Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the…
AplazadaMedia (4.9)0.47%—Bowo Code ExplorerAI4/2/202617/6/2026
The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via the 'file' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaAlta (8.4)0.54%—10-strike Network Inventory ExplorerAI28/1/202617/6/2026
10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code execution.
AnalizadaAlta (7.4)0.60%—Microsoft Azure Data Explorer22/1/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.
AplazadaAlta (7.1)0.27%—Dmytro Shteflyuk CodecolorerAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmytro Shteflyuk CodeColorer codecolorer allows Stored XSS.This issue affects CodeColorer: from n/a through <= 0.10.1.
AplazadaAlta (8.5)0.15%—Fspro Event LOG ExplorerAI21/1/202617/6/2026
Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations that will be executed with…
AplazadaMedia (5.1)0.36%—Markdown ExplorerAI16/1/202617/6/2026
Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads that execute in the application's privileged renderer context, allowing code execution on…