Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 1.9% | — | Meridian Technique Materialise OrthoviewAI | 23/6/2025 | 17/6/2026 | Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled. | |
| Aplazada | Media (6.5) | 0.19% | — | Etruel WP Views Counter WpecounterAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in etruel WP Views Counter wpecounter allows Stored XSS.This issue affects WP Views Counter: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.1) | 0.34% | — | Rustaurius Ultimate ReviewsAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Reflected XSS.This issue affects Ultimate Reviews: from n/a through <= 3.2.14. | |
| Aplazada | Media (6.4) | 0.27% | — | Game Review BlockAI | 13/6/2025 | 17/6/2026 | The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (8.6) | 0.72% | — | Microdicom Dicom ViewerAI | 10/6/2025 | 17/6/2026 | MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit the vulnerability in that the user must either visit a malicious website or… | |
| Aplazada | Alta (7.2) | 0.35% | — | LTL Freight Quotes Freightview EditionAILTL Freight Quotes Daylight EditionAILTL Freight Quotes DAY Ross EditionAI | 7/6/2025 | 17/6/2026 | The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11, 2.2.6 and 2.1.10 respectively, due to… | |
| Analizada | Alta (7.8) | 0.22% | — | Santesoft Dicom Viewer PRO | 6/6/2025 | 17/6/2026 | Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Aplazada | Media (6.4) | 0.22% | — | Freemind ViewerAI | 6/6/2025 | 17/6/2026 | The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.4) | 0.19% | — | Santesoft Dicom Viewer PRO | 29/5/2025 | 17/6/2026 | Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue to potentially disclose information and to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. | |
| Aplazada | Alta (7.5) | 0.61% | — | Crocoblock JetreviewsAI | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-reviews allows PHP Local File Inclusion.This issue affects JetReviews: from n/a through <= 2.3.6. | |
| Modificada | Media (6.5) | 0.33% | — | Proxymis Interview | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview interview allows SQL Injection.This issue affects Interview: from n/a through <= 1.01. | |
| Aplazada | Media (6.5) | 0.27% | — | Hitachi OPS Center Analyzer ViewpointAI | 16/5/2025 | 17/6/2026 | Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Ops Center Analyzer viewpoint: from 10.0.0-00 before 11.0.4-00. | |
| Analizada | Media (4.8) | 0.31% | — | Ljapps WP Google Review Slider | 15/5/2025 | 17/6/2026 | The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.3) | 0.18% | — | Bluetrait Blue Trait Event Viewer | 15/5/2025 | 17/6/2026 | The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Baja (2) | 0.33% | — | EsignaviewerAI | 15/5/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers. | |
| Analizada | Media (5.3) | 0.43% | — | Keking Kkfileview | 11/5/2025 | 17/6/2026 | A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Alta (8.8) | 0.88% | — | Wordpress Review PluginAI | 10/5/2025 | 17/6/2026 | The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.5 via the Post custom fields. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and… | |
| Aplazada | Media (6.9) | 0.29% | — | Osirix-viewer Osirix MDAI | 8/5/2025 | 17/6/2026 | Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash. | |
| Aplazada | Alta (8.7) | 0.97% | — | Osirix-viewer Osirix MDAI | 8/5/2025 | 17/6/2026 | Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition. | |
| Aplazada | Baja (3.1) | 0.34% | — | Discourse-code-reviewAI | 7/5/2025 | 17/6/2026 | The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the discourse-code-review plugin. As a workaround, one… | |
| Modificada | Crítica (9.8) | 0.30% | — | Wbcomdesigns Activity Link Preview FOR Buddypress | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddypress allows Server Side Request Forgery.This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through <= 1.4.4. | |
| Aplazada | Media (6.4) | 0.24% | — | Xavins Review RatingsAI | 3/5/2025 | 17/6/2026 | The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr' shortcode in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.6) | 0.46% | — | Microdicom Dicom ViewerAI | 1/5/2025 | 17/6/2026 | MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation. | |
| Aplazada | Alta (8.6) | 0.58% | — | Microdicom Dicom ViewerAI | 1/5/2025 | 17/6/2026 | MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file for exploitation. | |
| Analizada | Alta (8.1) | 0.36% | — | A3rev Page View Count | 1/5/2025 | 17/6/2026 | The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and… |