Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.32. | |
| Analizada | Media (4.7) | 0.24% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operator to follow a crafted authorization URL could execute JavaScript in the… | |
| Analizada | Media (5.3) | 0.34% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attacker can submit arbitrary URLs to perform internal network reconnaissance via an… | |
| Aplazada | Media (4.3) | 0.35% | — | Media Library AssistantAI | 5/3/2026 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Alta (8.8) | 0.78% | — | Music-assistant Music Assistant Server | 20/2/2026 | 17/6/2026 | Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API allows users to bypass the .m3u extension… | |
| Aplazada | Media (5.3) | 0.22% | — | Ays-chatgpt-assistantAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Loopus WP Virtual AssistantAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Stored XSS.This issue affects WP Virtual Assistant: from n/a through <= 3.1. | |
| Aplazada | Media (4.3) | 0.18% | — | Recorp Ai-content-writing-assistantAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One ai-content-writing-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, ChatGPT, Image… | |
| Analizada | Media (4) | 0.40% | — | Home-assistant | 23/12/2025 | 17/6/2026 | Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability. | |
| Aplazada | Media (5.3) | 0.35% | — | Davidlingren Media Library AssistantAI | 9/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n/a through <= 3.29. | |
| Analizada | Media (5.4) | 0.08% | — | HP Image Assistant | 3/12/2025 | 17/6/2026 | — | |
| Aplazada | Media (4) | 0.12% | — | Samsung Cloud AssistantAI | 2/12/2025 | 25/9/2026 | Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access partial data in sandbox. | |
| Aplazada | Alta (7.2) | 0.93% | 💥 PoC | S2B AI AssistantAI | 21/11/2025 | 17/6/2026 | The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, with Editor-level… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Driver AND Support AssistantAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may potentially… | |
| Analizada | Media (6.1) | 0.22% | — | Remyandrade FAQ BOT With AI Assistant | 7/11/2025 | 17/6/2026 | The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation. | |
| Aplazada | Alta (7.5) | 1.3% | 💥 Exploit | Ays-chatgpt-assistantAI | 6/11/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Retrieve Embedded Sensitive Data.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.6.6. | |
| Aplazada | Media (4.3) | 0.19% | — | AI Auto Tool Content Writing AssistantAI | 4/11/2025 | 17/6/2026 | The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.41% | — | Media Library AssistantAI | 18/10/2025 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive… | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface. | |
| Analizada | Crítica (9.9) | 0.50% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen. | |
| Analizada | Media (5.8) | 0.51% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders. | |
| Analizada | Media (5.8) | 0.38% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path. | |
| Analizada | Alta (7.7) | 0.54% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers. | |
| Analizada | Crítica (9.9) | 0.72% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation. | |
| Analizada | Alta (7.7) | 0.46% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users. |