Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3427 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | A3rev Page View Count | 1/5/2025 | 17/6/2026 | The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.26% | — | Andrey Mikhalchuk 360 ViewAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrey Mikhalchuk 360 View 360-view allows Stored XSS.This issue affects 360 View: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.1) | 0.24% | — | Mettler Toledo Freeweight.net WEB Reports ViewerAI | 22/4/2025 | 17/6/2026 | A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter. | |
| Aplazada | Alta (7.1) | 0.31% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center Analyzer Viewpoint OVFAI | 22/4/2025 | 17/6/2026 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF: from 10.0.0-00 before 11.0.0-04. | |
| Aplazada | Crítica (9.8) | 0.79% | — | Smart Product ReviewAI | 19/4/2025 | 17/6/2026 | The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code… | |
| Aplazada | Alta (8.8) | 0.37% | — | Starfish Review Generation AND MarketingAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows Privilege Escalation.This issue affects Starfish Review Generation & Marketing: from n/a through <= 3.1.19. | |
| Aplazada | Alta (7.1) | 0.15% | — | Review Wave Google Places ReviewsAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MessageMetric Review Wave – Google Places Reviews review-wave-google-places-reviews allows Stored XSS.This issue affects Review Wave – Google Places Reviews: from n/a through <= 1.4.7. | |
| Aplazada | Alta (7.1) | 0.29% | — | Bernd Altmeier Google Maps GPX ViewerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bernd Altmeier Google Maps GPX Viewer google-maps-gpx-viewer allows Reflected XSS.This issue affects Google Maps GPX Viewer: from n/a through <= 3.6. | |
| Analizada | Media (5.7) | 0.30% | — | Oracle Smart View FOR Office | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The supported version that is affected is 24.200. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Smart View for Office. Successful attacks… | |
| Modificada | Alta (7.8) | 0.29% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+13 | 15/4/2025 | 17/6/2026 | A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.38% | — | Autodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3DAutodesk Civil 3D+8 | 15/4/2025 | 17/6/2026 | A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (8.5) | 0.49% | — | Wpguru Error LOG ViewerAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log Viewer error-log-viewer-wp allows Blind SQL Injection.This issue affects Error Log Viewer: from n/a through <= 1.0.5. | |
| Aplazada | Alta (8.5) | 0.34% | — | Magnigenie Review-stars-count-for-woocommerceAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce review-stars-count-for-woocommerce allows SQL Injection.This issue affects Review Stars Count For WooCommerce: from n/a through <= 2.0. | |
| Analizada | Alta (8.5) | 0.20% | — | NI Labview | 9/4/2025 | 17/6/2026 | Out of bounds write vulnerability due to improper bounds checking in NI LabVIEW reading CPU info from cache that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Labview | 9/4/2025 | 17/6/2026 | Out of bounds write vulnerability due to improper bounds checking in NI LabVIEW in InitCPUInformation() that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and… | |
| Analizada | Alta (7) | 0.19% | — | NI Labview | 9/4/2025 | 17/6/2026 | There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability affects NI LabVIEW 2025 Q1 and… | |
| Analizada | Alta (7) | 0.19% | — | NI Labview | 9/4/2025 | 17/6/2026 | There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability… | |
| Aplazada | Media (5.9) | 0.29% | — | Grade Review StreamAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Grade Us, Inc. Review Stream review-stream allows Stored XSS.This issue affects Review Stream: from n/a through <= 1.6.7. | |
| Aplazada | Media (5.4) | 0.22% | — | Swiftxr 3darvr ViewerAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer swiftxr-3darvr-viewer allows Cross Site Request Forgery.This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.5) | 1.1% | — | Alex Prokopenko Just Post PreviewAIJustcoded Just Post PreviewAI | 4/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Prokopenko / JustCoded Just Post Preview Widget just-post-preview allows PHP Local File Inclusion.This issue affects Just Post Preview Widget: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Automationdirect C-more ViewjetAI | 4/4/2025 | 17/6/2026 | Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker. | |
| Aplazada | Media (5.8) | 0.46% | — | Automationdirect Viewjet C-moreAIAutomationdirect Gc-a2AI | 4/4/2025 | 17/6/2026 | Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack. | |
| Aplazada | Media (5.3) | 0.61% | — | Redlion Viewjet C-moreAIRedlion Gc-a2AI | 4/4/2025 | 17/6/2026 | Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) condition. | |
| Aplazada | Media (4.3) | 0.35% | — | HMI Viewjet C-moreAI | 4/4/2025 | 17/6/2026 | Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the product user to perform operations on the product's web pages. | |
| Aplazada | Alta (7.1) | 0.24% | — | Dustinscarberry MediaviewAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dustinscarberry MediaView mediaview allows Reflected XSS.This issue affects MediaView: from n/a through <= 1.1.2. |