Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

3322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.18%—Advance WP Query Search FilterAI30/12/20257/10/2026
El plugin de WordPress Advance WP Query Search Filter hasta la versión 1.0.10 no sanitiza ni escapa un parámetro antes de devolverlo en la página, lo que lleva a un cross-site scripting reflejado que podría ser utilizado contra usuarios con altos privilegios, como el administrador.
AplazadaMedia (6.1)0.18%—Advance WP Query Search FilterAI30/12/20257/10/2026
El plugin de WordPress Advance WP Query Search Filter hasta la versión 1.0.10 no sanitiza ni escapa un parámetro antes de devolverlo en la página, lo que lleva a un cross-site scripting reflejado que podría ser utilizado contra usuarios con altos privilegios, como administradores.
AplazadaMedia (6.5)0.21%—Crocoblock JetsearchAI29/12/20257/10/2026
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Crocoblock JetSearch permite XSS basado en DOM. Este problema afecta a JetSearch: desde n/d hasta 3.5.16.
AplazadaAlta (8.5)0.39%—GNU BarcodeAI24/12/202517/6/2026
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.
AnalizadaMedia (5.5)0.18%—Pdfforge PDF Architect23/12/202517/6/2026
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.45%—Pdfforge PDF Architect23/12/202517/6/2026
pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
AnalizadaAlta (7.8)0.19%—Pdfforge PDF Architect23/12/202517/6/2026
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
AnalizadaAlta (7)0.17%—Pdfforge PDF Architect23/12/202517/6/2026
pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
AnalizadaAlta (7.8)0.20%—Pdfforge PDF Architect23/12/202517/6/2026
pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…
AnalizadaAlta (7)0.17%—Pdfforge PDF Architect23/12/202517/6/2026
pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
AnalizadaMedia (6.5)0.32%—Learningcircuit Local Deep Research23/12/202517/6/2026
Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to…
AplazadaMedia (4.3)0.15%—WEB TO Sugarcrm LeadAI21/12/202517/6/2026
The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the custom field deletion functionality. This makes it possible for unauthenticated attackers to delete custom fields via a forged request…
AplazadaMedia (5.4)0.28%—FibosearchAI20/12/202517/6/2026
The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (8.5)0.16%—Arcsoft PhotostudioAI19/12/202517/6/2026
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions.
AplazadaMedia (4.7)0.33%—Esri Arcgis WEB AppbuilderAI19/12/202517/6/2026
There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the…
AplazadaAlta (7.5)0.27%—Arcsearch FOR IOSAI19/12/202517/6/2026
ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.
AplazadaAlta (7.4)0.23%—ArcsearchAI19/12/202517/6/2026
ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
AnalizadaMedia (4.9)0.38%—Elasticsearch18/12/202517/6/2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
AnalizadaMedia (5.3)0.41%—Elasticsearch Packetbeat18/12/202517/6/2026
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.
AnalizadaMedia (6.5)0.25%—Elasticsearch Packetbeat18/12/202517/6/2026
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.
AnalizadaMedia (6.5)0.46%—Elasticsearch Packetbeat18/12/202517/6/2026
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.
AnalizadaMedia (6.5)0.32%—Elasticsearch18/12/202530/9/2026
Asignación de recursos sin límites ni limitación (CWE-770) en Elasticsearch puede permitir que un usuario autenticado con bajos privilegios cause una asignación excesiva (CAPEC-130), provocando una denegación de servicio persistente (fallo por OOM) mediante el envío de datos de configuración de usuario de tamaño…
AplazadaAlta (7.1)0.21%—Marcomilesi Anac XML Bandi DI GaraAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Milesi ANAC XML Bandi di Gara avcp allows Reflected XSS.This issue affects ANAC XML Bandi di Gara: from n/a through <= 7.7.
AplazadaMedia (4.3)0.22%—Creativemindssolutions CM ON Demand Search AND ReplaceAI16/12/20257/10/2026
Vulnerabilidad de autorización faltante en CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a CM On Demand Search And Replace: desde n/a hasta menor o igual que…
AnalizadaAlta (7.4)0.19%—Elasticsearch15/12/20257/10/2026
Autenticación incorrecta en el reino PKI de Elasticsearch puede conducir a la suplantación de identidad de usuarios mediante certificados de cliente especialmente diseñados. Un actor malicioso necesitaría tener un certificado de cliente así diseñado firmado por una Autoridad de Certificación legítima y de confianza.