Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.19% | — | Siemens Sicam Toolbox II | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value. This could allow an attacker to execute an on-path… | |
| Analizada | Alta (7.7) | 0.19% | — | Siemens Sicam Toolbox II | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check the extended key usage attribute of that device's certificate. This could allow an attacker to execute an on-path… | |
| Analizada | Media (6.5) | 0.23% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | |
| Analizada | Alta (7.5) | 0.15% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | |
| Analizada | Crítica (9.8) | 0.63% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | |
| Analizada | Media (6.5) | 0.20% | — | Jetbrains Toolbox | 17/4/2025 | 17/6/2026 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin | |
| Aplazada | Media (5.9) | 0.28% | — | Rachel Cherry Wa11y THE WEB Accessibility ToolboxAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry wA11y – The Web Accessibility Toolbox wa11y allows Stored XSS.This issue affects wA11y – The Web Accessibility Toolbox: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.9) | 0.35% | — | Codetoolbox MY Bootstrap MenuAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetoolbox My Bootstrap Menu my-bootstrap-menu allows Stored XSS.This issue affects My Bootstrap Menu: from n/a through <= 1.2.1. | |
| Aplazada | Alta (7.1) | 0.35% | — | Immosoft Immotoolbox ConnectAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImmoSoft ImmoToolBox Connect immotoolbox-connect allows Reflected XSS.This issue affects ImmoToolBox Connect: from n/a through <= 1.3.3. | |
| Aplazada | Media (6.1) | 0.41% | — | Website Toolbox CommunityAI | 12/12/2024 | 17/6/2026 | The Website Toolbox Community plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘websitetoolbox_username’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.5) | 0.31% | — | Mark Hodder Themedy ToolboxAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Hodder Themedy Toolbox themedy-toolbox allows DOM-Based XSS.This issue affects Themedy Toolbox: from n/a through <= 1.0.16. | |
| Analizada | Media (5.4) | 0.40% | — | Themedy Toolbox | 26/9/2024 | 17/6/2026 | The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, themedy_social_link, themedy_alertbox, and themedy_pullleft shortcodes in all versions up to, and including, 1.0.14, and up to, and including 1.0.15 for the plugin's themedy_button shortcode due to… | |
| Modificada | Alta (7.8) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.18% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Media (5.5) | 0.25% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Alta (7.8) | 0.34% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.18% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Media (5.5) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Media (5.5) | 0.21% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Alta (7.8) | 0.19% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Media (5.4) | 0.28% | — | Athemes Sydney Toolbox | 14/5/2024 | 17/6/2026 | The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |