Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.18% | — | Advance WP Query Search FilterAI | 30/12/2025 | 7/10/2026 | El plugin de WordPress Advance WP Query Search Filter hasta la versión 1.0.10 no sanitiza ni escapa un parámetro antes de devolverlo en la página, lo que lleva a un cross-site scripting reflejado que podría ser utilizado contra usuarios con altos privilegios, como el administrador. | |
| Aplazada | Media (6.1) | 0.18% | — | Advance WP Query Search FilterAI | 30/12/2025 | 7/10/2026 | El plugin de WordPress Advance WP Query Search Filter hasta la versión 1.0.10 no sanitiza ni escapa un parámetro antes de devolverlo en la página, lo que lleva a un cross-site scripting reflejado que podría ser utilizado contra usuarios con altos privilegios, como administradores. | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JetsearchAI | 29/12/2025 | 7/10/2026 | Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Crocoblock JetSearch permite XSS basado en DOM. Este problema afecta a JetSearch: desde n/d hasta 3.5.16. | |
| Aplazada | Alta (8.5) | 0.39% | — | GNU BarcodeAI | 24/12/2025 | 17/6/2026 | GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system. | |
| Analizada | Media (5.5) | 0.18% | — | Pdfforge PDF Architect | 23/12/2025 | 17/6/2026 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.45% | — | Pdfforge PDF Architect | 23/12/2025 | 17/6/2026 | pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.19% | — | Pdfforge PDF Architect | 23/12/2025 | 17/6/2026 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7) | 0.17% | — | Pdfforge PDF Architect | 23/12/2025 | 17/6/2026 | pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.20% | — | Pdfforge PDF Architect | 23/12/2025 | 17/6/2026 | pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Alta (7) | 0.17% | — | Pdfforge PDF Architect | 23/12/2025 | 17/6/2026 | pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (6.5) | 0.32% | — | Learningcircuit Local Deep Research | 23/12/2025 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to… | |
| Aplazada | Media (4.3) | 0.15% | — | WEB TO Sugarcrm LeadAI | 21/12/2025 | 17/6/2026 | The Web to SugarCRM Lead plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the custom field deletion functionality. This makes it possible for unauthenticated attackers to delete custom fields via a forged request… | |
| Aplazada | Media (5.4) | 0.28% | — | FibosearchAI | 20/12/2025 | 17/6/2026 | The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.5) | 0.16% | — | Arcsoft PhotostudioAI | 19/12/2025 | 17/6/2026 | Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions. | |
| Aplazada | Media (4.7) | 0.33% | — | Esri Arcgis WEB AppbuilderAI | 19/12/2025 | 17/6/2026 | There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the… | |
| Aplazada | Alta (7.5) | 0.27% | — | Arcsearch FOR IOSAI | 19/12/2025 | 17/6/2026 | ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk. | |
| Aplazada | Alta (7.4) | 0.23% | — | ArcsearchAI | 19/12/2025 | 17/6/2026 | ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | |
| Analizada | Media (4.9) | 0.38% | — | Elasticsearch | 18/12/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request. | |
| Analizada | Media (5.3) | 0.41% | — | Elasticsearch Packetbeat | 18/12/2025 | 17/6/2026 | Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat. | |
| Analizada | Media (6.5) | 0.25% | — | Elasticsearch Packetbeat | 18/12/2025 | 17/6/2026 | Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages. | |
| Analizada | Media (6.5) | 0.46% | — | Elasticsearch Packetbeat | 18/12/2025 | 17/6/2026 | Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number. | |
| Analizada | Media (6.5) | 0.32% | — | Elasticsearch | 18/12/2025 | 30/9/2026 | Asignación de recursos sin límites ni limitación (CWE-770) en Elasticsearch puede permitir que un usuario autenticado con bajos privilegios cause una asignación excesiva (CAPEC-130), provocando una denegación de servicio persistente (fallo por OOM) mediante el envío de datos de configuración de usuario de tamaño… | |
| Aplazada | Alta (7.1) | 0.21% | — | Marcomilesi Anac XML Bandi DI GaraAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Milesi ANAC XML Bandi di Gara avcp allows Reflected XSS.This issue affects ANAC XML Bandi di Gara: from n/a through <= 7.7. | |
| Aplazada | Media (4.3) | 0.22% | — | Creativemindssolutions CM ON Demand Search AND ReplaceAI | 16/12/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a CM On Demand Search And Replace: desde n/a hasta menor o igual que… | |
| Analizada | Alta (7.4) | 0.19% | — | Elasticsearch | 15/12/2025 | 7/10/2026 | Autenticación incorrecta en el reino PKI de Elasticsearch puede conducir a la suplantación de identidad de usuarios mediante certificados de cliente especialmente diseñados. Un actor malicioso necesitaría tener un certificado de cliente así diseñado firmado por una Autoridad de Certificación legítima y de confianza. |