Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Media (5.4) | 0.37% | — | Wptinysolutions Media Library Tools | 21/11/2024 | 17/6/2026 | The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Aplazada | Alta (7.1) | 0.20% | — | Matt Rude MDR Webmaster ToolsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matt Rude MDR Webmaster Tools mdr-webmaster-tools allows Stored XSS.This issue affects MDR Webmaster Tools: from n/a through <= 1.1. | |
| Aplazada | Media (4.9) | 0.54% | — | Toolstack Cyan BackupAI | 18/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Basepress Migration ToolsAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration-tools allows Upload a Web Shell to a Web Server.This issue affects BasePress Migration Tools: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (10) | 0.69% | — | Ventilator Manufacturer Ventilator Service ToolsAI | 14/11/2024 | 17/6/2026 | The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software via the… | |
| Analizada | Crítica (9.8) | 1.3% | — | Gnome GlibDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Tools | 11/11/2024 | 17/6/2026 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | |
| Modificada | Alta (7.5) | 1.7% | — | Apache TomcatNetapp Ontap Tools | 7/11/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35… | |
| Modificada | Media (6.1) | 0.31% | — | Samglover Client Power Tools | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal client-power-tools allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through <= 1.9.0. | |
| Modificada | Media (6.6) | 1.4% | — | Ruby-lang RexmlNetapp Ontap Tools | 28/10/2024 | 17/6/2026 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later… | |
| Analizada | Media (4.4) | 0.38% | — | Solarwinds Kiwi Cattools | 17/10/2024 | 17/6/2026 | SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes. | |
| Analizada | Baja (1.8) | 0.29% | — | Microfocus Application Automation Tools | 16/10/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools.… | |
| Analizada | Media (5.1) | 0.40% | — | Microfocus Application Automation Tools | 16/10/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below. | |
| Analizada | Baja (1.8) | 0.29% | — | Microfocus Application Automation Tools | 16/10/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability… | |
| Analizada | Media (5.9) | 0.47% | — | Microfocus Application Automation Tools | 16/10/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below. | |
| Analizada | Media (5.9) | 0.47% | — | Microfocus Application Automation Tools | 16/10/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below. | |
| Modificada | Alta (8.8) | 0.58% | — | Oracle Peoplesoft Enterprise Peopletools | 15/10/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Analizada | Alta (8.1) | 0.52% | — | Oracle Peoplesoft Enterprise Peopletools | 15/10/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful… | |
| Modificada | Media (6.1) | 0.20% | — | Oracle Peoplesoft Enterprise Peopletools | 15/10/2024 | 21/8/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Aplazada | Media (6.4) | 0.33% | — | Toolstack Auto IframeAI | 9/10/2024 | 17/6/2026 | The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.31% | — | Prontotools Login Logout Shortcode | 4/10/2024 | 17/6/2026 | The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (4.3) | 1.3% | — | Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+4 | 3/10/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0… | |
| Analizada | Media (4.8) | 0.46% | — | Starcitizen.tools Citizen | 30/9/2024 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0. |