Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.58%💥 PoCLive2d Cubism Editor3/3/202317/6/2026
Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info Table in an MOC3 file.
ModificadaAlta (8.8)0.26%—Orchestrated Corona Virus (covid-19) Banner & Live Data14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7.0.6 versions.
ModificadaCrítica (9.8)1.1%—Liveboxcloud Vdesk31/1/202317/6/2026
An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in…
ModificadaAlta (7.5)1.0%—Citrix Application Delivery ControllerCitrix Gateway26/1/202317/6/2026
Unauthenticated denial of service
ModificadaMedia (6.5)0.99%—Citrix GatewayCitrix Application Delivery Controller26/1/202317/6/2026
Authenticated denial of service
ModificadaAlta (8.8)0.42%—Edgenexus Application Delivery Controller23/1/202317/6/2026
A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)3.5%—Edgenexus Application Delivery Controller23/1/202317/6/2026
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via…
ModificadaAlta (8.6)0.86%—Cisco Broadworks Application Delivery Platform Device ManagementCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input…
ModificadaMedia (6.1)0.59%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of…
ModificadaCrítica (9.8)0.69%—Glidernet Ogn-live5/1/202317/6/2026
A vulnerability, which was classified as critical, has been found in glidernet ogn-live. This issue affects some unknown processing. The manipulation leads to sql injection. The patch is named bc0f19965f760587645583b7624d66a260946e01. It is recommended to apply a patch to fix this issue. The associated identifier of…
ModificadaMedia (6.5)0.59%—Citrix Application Delivery Controller FirmwareCitrix Gateway26/12/202217/6/2026
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
ModificadaMedia (6.1)0.54%—Dash-live Project Dash-live25/12/202217/6/2026
A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is…
AnalizadaCrítica (9.8)6.7%⚠ Explotación activa💥 PoCCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
ModificadaMedia (4.8)0.47%—Livemeshelementor Addons FOR Elementor12/12/202217/6/2026
The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaCrítica (9.8)0.64%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
User login brute force protection functionality bypass
ModificadaCrítica (9.6)0.29%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Remote desktop takeover via phishing
ModificadaCrítica (9.8)1.1%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Unauthorized access to Gateway user capabilities
ModificadaAlta (7.6)0.12%—Alivecor Kardiamobile FirmwareAlivecor Kardiamobile 6L FirmwareAlivecor Kardiamobile Card Firmware27/10/202217/6/2026
The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar…
ModificadaMedia (6.1)0.34%—Alivecor Kardia26/10/202217/6/2026
CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.
ModificadaMedia (4.8)0.62%—Retain Live Chat25/10/202217/6/2026
The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6)0.17%—AsusliveupdateAsussoftwaremangerAsus System Control Interface18/10/202217/6/2026
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0,…
ModificadaBaja (3.3)0.17%—Samsung Sharelive7/10/202217/6/2026
Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.
ModificadaAlta (7.5)1.9%💥 ExploitSoftlinkint Oliver V5 Library1/9/202217/6/2026
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.
ModificadaMedia (5.3)1.9%💥 ExploitSearchwp Live Ajax Search15/8/202217/6/2026
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink
ModificadaMedia (6.1)0.52%—Citrix GatewayCitrix Application Delivery Controller Firmware28/7/202217/6/2026
Unauthenticated redirection to a malicious website