Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.65% | — | VegaAIVega SelectionsAI | 14/2/2025 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to version 5.26.0 of vega and 5.4.2 of vega-selections, the `vlSelectionTuples` function can be used to call JavaScript functions, leading to cross-site scripting.`vlSelectionTuples` calls… | |
| Aplazada | Media (4.3) | 0.43% | — | Josevega Display Custom Fields IN THE Frontend Post AND User Profile FieldsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0. | |
| Aplazada | Alta (7.5) | 0.52% | — | Vegam Solutions Vegam 4IAI | 20/11/2024 | 17/6/2026 | A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print label function. Specifically, the filePathList parameter is susceptible to LFI, enabling a malicious user to include files from the web server, such… | |
| Analizada | Crítica (9.3) | 0.87% | — | Matrixcomsec Cosec Vega Faxq Firmware | 25/10/2024 | 17/6/2026 | This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Vegabird VookiAI | 7/10/2024 | 5/7/2026 | A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Vegabird YaazhiniAI | 7/10/2024 | 5/7/2026 | A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe. | |
| Modificada | Alta (8.8) | 1.1% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible… | |
| Modificada | Media (4.3) | 0.47% | — | Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.41% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Alta (7.5) | 0.97% | — | Davegamble Cjson | 14/12/2023 | 17/6/2026 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. | |
| Modificada | Alta (7.5) | 1.5% | — | Davegamble Cjson | 14/12/2023 | 17/6/2026 | cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. | |
| Modificada | Alta (7.5) | 1.3% | 💥 PoC | AMD Radeon SoftwareAMD Radeon RX Vega 56 FirmwareAMD Radeon RX Vega 64 FirmwareAMD Radeon PRO Vega 56 Firmware+1 | 14/11/2023 | 17/6/2026 | Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service. | |
| Modificada | Media (6.7) | 0.16% | — | Intel Radeon RX Vega M FirmwareAMD Radeon SoftwareAMD Radeon RX Vega 56 FirmwareAMD Radeon RX Vega 64 Firmware+2 | 14/11/2023 | 17/6/2026 | Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution. | |
| Modificada | Media (6.7) | 0.16% | — | Intel Radeon RX Vega M FirmwareAMD Radeon SoftwareAMD Radeon RX Vega 56 FirmwareAMD Radeon RX Vega 64 Firmware+2 | 14/11/2023 | 17/6/2026 | Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.21% | — | Intel Radeon RX Vega M FirmwareAMD Radeon SoftwareAMD Radeon RX Vega 56 FirmwareAMD Radeon RX Vega 64 Firmware+2 | 14/11/2023 | 17/6/2026 | Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service. | |
| Modificada | Crítica (9.8) | 0.63% | — | Vegagroup WEB Collection | 13/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection. This issue affects Web Collection: before 31197. | |
| Modificada | Media (5.2) | 0.49% | — | Gobalsky Vega | 23/6/2023 | 17/6/2026 | Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to version 0.71.6, a vulnerability exists that allows a malicious validator to trick the Vega network into re-processing past Ethereum events from Vega’s Ethereum bridge. For example, a deposit to the… | |
| Modificada | Crítica (9.8) | 0.64% | — | Vegayazilim Mobile Assistant | 17/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343. | |
| Modificada | Media (6.1) | 0.81% | — | Vega-functions Project Vega-functionsVega Project Vega | 4/3/2023 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.`lassoAppend' function accepts 3 arguments and internally invokes `push` function on the 1st argument specifying array consisting of 2nd and 3rd arguments as `push` call argument. The type of the… | |
| Modificada | Media (6.1) | 0.78% | — | Vega-functions Project Vega-functionsVega Project Vega | 4/3/2023 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. The Vega `scale` expression function has the ability to call arbitrary functions with a single controlled argument. The scale expression function passes a user supplied argument group to getScale,… | |
| Modificada | Media (6.1) | 0.52% | — | Webapplication-veganguide Project Webapplication-veganguide | 17/1/2023 | 17/6/2026 | A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the argument country/city leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Media (5.5) | 0.26% | — | AMD Enterprise DriverAMD Radeon PRO SoftwareAMD Radeon SoftwareAMD Radeon RX Vega 56 Firmware+63 | 9/11/2022 | 17/6/2026 | Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality. | |
| Modificada | Alta (7.8) | 0.27% | — | AMD Enterprise DriverAMD Radeon PRO SoftwareAMD Radeon SoftwareAMD Radeon RX Vega 56 Firmware+99 | 9/11/2022 | 17/6/2026 | Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA. | |
| Modificada | Alta (7.8) | 0.18% | — | AMD Enterprise DriverAMD Radeon PRO SoftwareAMD Radeon SoftwareAMD Radeon RX Vega 56 Firmware+22 | 9/11/2022 | 17/6/2026 | Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel. | |
| Modificada | Alta (7.8) | 0.26% | — | AMD Enterprise DriverAMD Radeon PRO SoftwareAMD Radeon SoftwareAMD Radeon RX Vega 56 Firmware+99 | 9/11/2022 | 17/6/2026 | Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. |