Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
5121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.1) | 0.31% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Baja (2.1) | 0.33% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Media (5.5) | 0.40% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Media (4.8) | 0.38% | — | Mediawiki Checkuser | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2. | |
| Analizada | Baja (2.3) | 0.43% | — | Wikimedia Scribunto | 11/5/2026 | 11/8/2026 | Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2. | |
| Analizada | Baja (1.3) | 0.40% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Media (5.1) | 0.37% | — | Mediawiki | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Pendiente de análisis | Baja (2.1) | 0.32% | — | Wikimedia AbusefilterAI | 11/5/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Analizada | Media (6.7) | 0.15% | — | Mediatek Mt8115 FirmwareMediatek Mt8186 FirmwareMediatek Mt8188 FirmwareMediatek Mt8196 Firmware+28 | 4/5/2026 | 17/6/2026 | In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504. | |
| Analizada | Media (6.5) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6833 FirmwareMediatek Mt6835 Firmware+47 | 4/5/2026 | 17/6/2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620;… | |
| Analizada | Media (6.5) | 0.22% | — | Mediatek Mt6763 FirmwareMediatek Mt6765 FirmwareMediatek Mt6767 FirmwareMediatek Mt6768 Firmware+64 | 4/5/2026 | 17/6/2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue… | |
| Analizada | Media (6.7) | 0.15% | — | Mediatek Mt6765 FirmwareMediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 Firmware+18 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281. | |
| Analizada | Media (6.7) | 0.11% | — | Mediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 FirmwareMediatek Mt6899 Firmware+13 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296. | |
| Aplazada | Baja (2.1) | 0.42% | — | AV Stumpfl Pixera TWO Media ServerAI | 3/5/2026 | 17/6/2026 | A vulnerability has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. The affected element is an unknown function of the component Service Port 1338. Such manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 25.2 R3 is sufficient to fix… | |
| Aplazada | Media (6.5) | 0.34% | — | Najeebmedia Frontend File ManagerAI | 3/5/2026 | 17/6/2026 | During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user… | |
| Analizada | Media (6.3) | 0.13% | — | Nvidia Nemoclaw | 28/4/2026 | 17/6/2026 | NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this… | |
| Analizada | Alta (8.6) | 0.40% | — | Nvidia Nemoclaw | 28/4/2026 | 17/6/2026 | NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A… | |
| Analizada | Media (6.5) | 0.36% | — | Nvidia Nvflare | 28/4/2026 | 17/6/2026 | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure. | |
| Analizada | Alta (8.8) | 0.48% | — | Nvidia Nvflare | 28/4/2026 | 17/6/2026 | NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution. | |
| Analizada | Crítica (9.8) | 0.57% | — | Nvidia Nvflare | 28/4/2026 | 17/6/2026 | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code… | |
| Aplazada | Media (6.9) | 0.40% | — | Klik SocialmediawebsiteAI | 25/4/2026 | 17/6/2026 | A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely. | |
| Pendiente de análisis | Alta (8.2) | 0.32% | — | Nvidia Cuda-qAI | 21/4/2026 | 17/6/2026 | NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure. | |
| Pendiente de análisis | Alta (7.7) | 0.24% | — | Nvidia KAI SchedulerAI | 21/4/2026 | 17/6/2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Nvidia KAI SchedulerAI | 21/4/2026 | 17/6/2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering. | |
| Aplazada | Media (5.1) | 0.29% | — | Semantic-mediawiki Semantic MediawikiAI | 21/4/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal… |