Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.28%—Pdf-xchange Pdf-toolsPdf-xchange Editor22/11/202417/6/2026
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…
AnalizadaAlta (7.8)0.28%—Pdf-xchange Pdf-toolsPdf-xchange Editor22/11/202417/6/2026
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…
AnalizadaAlta (7.8)0.28%—Pdf-xchange Pdf-toolsPdf-xchange Editor22/11/202417/6/2026
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…
AnalizadaMedia (5.4)0.37%—Wptinysolutions Media Library Tools21/11/202417/6/2026
The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
AplazadaAlta (7.1)0.20%—Matt Rude MDR Webmaster ToolsAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Matt Rude MDR Webmaster Tools mdr-webmaster-tools allows Stored XSS.This issue affects MDR Webmaster Tools: from n/a through <= 1.1.
AplazadaMedia (4.9)0.54%—Toolstack Cyan BackupAI18/11/202417/6/2026
Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3.
AplazadaCrítica (9.9)0.49%—Basepress Migration ToolsAI16/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration-tools allows Upload a Web Shell to a Web Server.This issue affects BasePress Migration Tools: from n/a through <= 1.0.0.
AplazadaCrítica (10)0.69%—Ventilator Manufacturer Ventilator Service ToolsAI14/11/202417/6/2026
The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software via the…
AnalizadaCrítica (9.8)1.3%—Gnome GlibDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Tools11/11/202417/6/2026
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
ModificadaAlta (7.5)1.7%—Apache TomcatNetapp Ontap Tools7/11/202417/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35…
ModificadaMedia (6.1)0.31%—Samglover Client Power Tools29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal client-power-tools allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through <= 1.9.0.
ModificadaMedia (6.6)1.4%—Ruby-lang RexmlNetapp Ontap Tools28/10/202417/6/2026
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later…
AnalizadaMedia (4.4)0.38%—Solarwinds Kiwi Cattools17/10/202417/6/2026
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.
AnalizadaBaja (1.8)0.29%—Microfocus Application Automation Tools16/10/202417/6/2026
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools.…
AnalizadaMedia (5.1)0.40%—Microfocus Application Automation Tools16/10/202417/6/2026
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
AnalizadaBaja (1.8)0.29%—Microfocus Application Automation Tools16/10/202417/6/2026
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability…
AnalizadaMedia (5.9)0.47%—Microfocus Application Automation Tools16/10/202417/6/2026
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
AnalizadaMedia (5.9)0.47%—Microfocus Application Automation Tools16/10/202417/6/2026
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
ModificadaAlta (8.8)0.58%—Oracle Peoplesoft Enterprise Peopletools15/10/202417/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.…
AnalizadaAlta (8.1)0.52%—Oracle Peoplesoft Enterprise Peopletools15/10/202417/6/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful…
ModificadaMedia (6.1)0.20%—Oracle Peoplesoft Enterprise Peopletools15/10/202421/8/2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise…
AplazadaMedia (6.4)0.33%—Toolstack Auto IframeAI9/10/202417/6/2026
The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web…
AnalizadaMedia (5.4)0.31%—Prontotools Login Logout Shortcode4/10/202417/6/2026
The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaMedia (4.3)1.3%—Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+43/10/202417/6/2026
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0…
AnalizadaMedia (4.8)0.46%—Starcitizen.tools Citizen30/9/202417/6/2026
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
Orbitaley — Vulnerabilidades