Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

538 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.65%—Parallaxis Cuckoo ClockAI7/2/202617/6/2026
Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution with potential remote…
ModificadaAlta (8.1)0.60%—Parall Jspdf2/2/202618/8/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject…
AnalizadaAlta (8.7)0.63%—Parall Jspdf2/2/202617/6/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful BMP file that results in out of memory errors…
AnalizadaMedia (6.9)0.29%—Parall Jspdf2/2/202617/6/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function allows users to inject arbitrary XML. If given the possibility to pass unsanitized input to the addMetadata method, a user can inject arbitrary XMP metadata into the generated PDF. If the…
AnalizadaMedia (6.3)0.28%—Parall Jspdf2/2/202617/6/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requests. If multiple…
AplazadaMedia (5.8)0.18%—Cjjparadoxmax Synergy-project-managerAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Synergy Project Manager synergy-project-manager allows Stored XSS.This issue affects Synergy Project Manager: from n/a through <= 1.5.
AnalizadaMedia (5.1)0.28%—Juniper Paragon Automation15/1/202617/6/2026
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface…
ModificadaCrítica (9.2)2.2%—Parall Jspdf5/1/202630/9/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary…
AnalizadaAlta (7.5)0.73%—Symphorien Nixseparatedebuginfod30/12/202517/6/2026
nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.
AplazadaAlta (7.1)0.27%—Bplugins Parallax SectionAI18/12/202517/6/2026
Missing Authorization vulnerability in bPlugins Parallax Section block parallax-section allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Parallax Section block: from n/a through <= 1.0.9.
ModificadaAlta (8.1)0.53%—Axiomthemes Paragon18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Paragon paragon allows PHP Local File Inclusion.This issue affects Paragon: from n/a through <= 1.1.
AplazadaAlta (8.1)0.50%—Ankorathemes Ludos ParadiseAI18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ludos Paradise ludos-paradise allows PHP Local File Inclusion.This issue affects Ludos Paradise: from n/a through <= 2.1.3.
AnalizadaMedia (6.5)0.24%—Kashipara Ecommerce Website17/11/202517/6/2026
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.
AnalizadaMedia (6.5)0.24%—Kashipara Ecommerce Website17/11/202517/6/2026
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.
AnalizadaMedia (6.1)0.22%—Kashipara School Management System17/11/202517/6/2026
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
AnalizadaMedia (6.1)0.22%—Kashipara School Management System17/11/202517/6/2026
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.
AnalizadaMedia (6.5)0.24%—Kashipara Ecommerce Website17/11/202517/6/2026
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.
AplazadaAlta (7.3)0.20%—Siemens PS Iges Parasolid Translator ComponentAISiemens Simcenter FemapAISiemens Solid EdgeAI17/11/202517/6/2026
A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This…
AnalizadaMedia (5.4)0.26%—Jenkins Extensible Choice Parameter29/10/202517/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.
AnalizadaMedia (6.1)0.27%—Paracrawl Keops19/9/202517/6/2026
Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.
AplazadaMedia (4.7)0.24%—Parasut Software BizmuAI18/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Bizmu allows Cross-Site Scripting (XSS). This issue affects Bizmu: from 2.27.0 through 20250212.
AplazadaMedia (4.7)0.24%—Parasut Software ParasutAI17/9/202525/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Paraşüt allows Cross-Site Scripting (XSS). This issue affects Paraşüt: from 0.0.0.65efa44e through 20250204.
AplazadaMedia (6.5)0.17%—ALI Aghdam Aparat Video ShortcodeAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Aghdam Aparat Video Shortcode aparat-shortcode allows Stored XSS.This issue affects Aparat Video Shortcode: from n/a through <= 0.2.4.
AplazadaMedia (4.3)0.15%—Snagysandor Parallax-scrolling-enllax-jsAI5/9/202530/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in snagysandor Parallax Scrolling Enllax.js parallax-scrolling-enllax-js allows Cross Site Request Forgery.This issue affects Parallax Scrolling Enllax.js: from n/a through <= 0.0.6.
AplazadaMedia (6.5)0.21%—Snagysandor Parallax Scrolling Enllax.jsAI5/9/202530/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snagysandor Parallax Scrolling Enllax.js parallax-scrolling-enllax-js allows Stored XSS.This issue affects Parallax Scrolling Enllax.js: from n/a through <= 0.0.6.