Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.65% | — | Parallaxis Cuckoo ClockAI | 7/2/2026 | 17/6/2026 | Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution with potential remote… | |
| Modificada | Alta (8.1) | 0.60% | — | Parall Jspdf | 2/2/2026 | 18/8/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject… | |
| Analizada | Alta (8.7) | 0.63% | — | Parall Jspdf | 2/2/2026 | 17/6/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful BMP file that results in out of memory errors… | |
| Analizada | Media (6.9) | 0.29% | — | Parall Jspdf | 2/2/2026 | 17/6/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function allows users to inject arbitrary XML. If given the possibility to pass unsanitized input to the addMetadata method, a user can inject arbitrary XMP metadata into the generated PDF. If the… | |
| Analizada | Media (6.3) | 0.28% | — | Parall Jspdf | 2/2/2026 | 17/6/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requests. If multiple… | |
| Aplazada | Media (5.8) | 0.18% | — | Cjjparadoxmax Synergy-project-managerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Synergy Project Manager synergy-project-manager allows Stored XSS.This issue affects Synergy Project Manager: from n/a through <= 1.5. | |
| Analizada | Media (5.1) | 0.28% | — | Juniper Paragon Automation | 15/1/2026 | 17/6/2026 | A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface… | |
| Modificada | Crítica (9.2) | 2.2% | — | Parall Jspdf | 5/1/2026 | 30/9/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary… | |
| Analizada | Alta (7.5) | 0.73% | — | Symphorien Nixseparatedebuginfod | 30/12/2025 | 17/6/2026 | nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal. | |
| Aplazada | Alta (7.1) | 0.27% | — | Bplugins Parallax SectionAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in bPlugins Parallax Section block parallax-section allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Parallax Section block: from n/a through <= 1.0.9. | |
| Modificada | Alta (8.1) | 0.53% | — | Axiomthemes Paragon | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Paragon paragon allows PHP Local File Inclusion.This issue affects Paragon: from n/a through <= 1.1. | |
| Aplazada | Alta (8.1) | 0.50% | — | Ankorathemes Ludos ParadiseAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ludos Paradise ludos-paradise allows PHP Local File Inclusion.This issue affects Ludos Paradise: from n/a through <= 2.1.3. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php. | |
| Analizada | Media (6.1) | 0.22% | — | Kashipara School Management System | 17/11/2025 | 17/6/2026 | kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php. | |
| Analizada | Media (6.1) | 0.22% | — | Kashipara School Management System | 17/11/2025 | 17/6/2026 | kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php. | |
| Aplazada | Alta (7.3) | 0.20% | — | Siemens PS Iges Parasolid Translator ComponentAISiemens Simcenter FemapAISiemens Solid EdgeAI | 17/11/2025 | 17/6/2026 | A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This… | |
| Analizada | Media (5.4) | 0.26% | — | Jenkins Extensible Choice Parameter | 29/10/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code. | |
| Analizada | Media (6.1) | 0.27% | — | Paracrawl Keops | 19/9/2025 | 17/6/2026 | Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php. | |
| Aplazada | Media (4.7) | 0.24% | — | Parasut Software BizmuAI | 18/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Bizmu allows Cross-Site Scripting (XSS). This issue affects Bizmu: from 2.27.0 through 20250212. | |
| Aplazada | Media (4.7) | 0.24% | — | Parasut Software ParasutAI | 17/9/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Paraşüt allows Cross-Site Scripting (XSS). This issue affects Paraşüt: from 0.0.0.65efa44e through 20250204. | |
| Aplazada | Media (6.5) | 0.17% | — | ALI Aghdam Aparat Video ShortcodeAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Aghdam Aparat Video Shortcode aparat-shortcode allows Stored XSS.This issue affects Aparat Video Shortcode: from n/a through <= 0.2.4. | |
| Aplazada | Media (4.3) | 0.15% | — | Snagysandor Parallax-scrolling-enllax-jsAI | 5/9/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in snagysandor Parallax Scrolling Enllax.js parallax-scrolling-enllax-js allows Cross Site Request Forgery.This issue affects Parallax Scrolling Enllax.js: from n/a through <= 0.0.6. | |
| Aplazada | Media (6.5) | 0.21% | — | Snagysandor Parallax Scrolling Enllax.jsAI | 5/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snagysandor Parallax Scrolling Enllax.js parallax-scrolling-enllax-js allows Stored XSS.This issue affects Parallax Scrolling Enllax.js: from n/a through <= 0.0.6. |