Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
1900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.39% | — | Cognex In-sight ExplorerAICognex In-sight CameraAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as the In-Sight Explorer tool, to perform management operations such as changing network settings or modifying users' access to the device. | |
| Aplazada | Alta (7.2) | 0.31% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device… | |
| Aplazada | Alta (8.1) | 0.26% | — | Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI | 20/8/2025 | 17/6/2026 | There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions… | |
| Aplazada | Media (4.3) | 0.24% | — | Runzero ExplorerAIBrotherAI | 12/8/2025 | 17/6/2026 | By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described by CVE-2024-51978 to calculate the default administrator… | |
| Modificada | Baja (2.1) | 0.40% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade the affected component. The action taken… | |
| Modificada | Baja (2.9) | 0.59% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack… | |
| Modificada | Baja (2.1) | 0.29% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue.… | |
| Aplazada | Media (5.1) | 0.65% | — | Ready File ExplorerAI | 16/4/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file. | |
| Aplazada | Media (5) | 0.18% | — | Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI | 6/4/2025 | 17/6/2026 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access… | |
| Aplazada | Alta (7.1) | 0.37% | — | Mbyte Explore PagesAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mbyte Explore pages explore-pages allows Reflected XSS.This issue affects Explore pages: from n/a through <= 1.01. | |
| Aplazada | Alta (7.1) | 0.14% | — | Blightly ExplorerAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0. | |
| Analizada | Media (6.5) | 0.55% | — | Dhtmlx File Explorer | 7/2/2025 | 17/6/2026 | Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality. | |
| Analizada | Media (6.5) | 0.75% | — | Dhtmlx File Explorer | 7/2/2025 | 17/6/2026 | Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function. | |
| Aplazada | Alta (7.1) | 0.19% | — | Campusexplorer WidgetAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through <= 1.1. | |
| Modificada | Media (4.9) | 0.52% | — | Bowo Code Explorer | 30/10/2024 | 17/6/2026 | The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress… | |
| Modificada | Media (6.1) | 0.29% | — | Campusexplorer Widget | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CampusExplorer Campus Explorer Widget campus-explorer-widget allows Reflected XSS.This issue affects Campus Explorer Widget: from n/a through <= 1.4. | |
| Aplazada | Media (6.1) | 0.26% | — | Splunk Config ExplorerAI | 27/5/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product. | |
| Aplazada | Media (4.2) | 0.27% | — | Sysinternals Process ExplorerAI | 7/5/2024 | 17/6/2026 | Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling. | |
| Aplazada | Media (6.1) | 0.39% | — | Amazon Aws-js-s3-explorerAI | 11/3/2024 | 17/6/2026 | Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html. | |
| Modificada | Media (5.5) | 0.30% | — | Nsasoft Product KEY Explorer | 21/1/2024 | 17/6/2026 | A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit… | |
| Modificada | Alta (7.8) | 0.19% | — | Explorerplusplus Explorer++ | 17/1/2024 | 17/6/2026 | Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler (SEH) records. | |
| Modificada | Alta (7.8) | 0.26% | — | Fit2cloud Cloudexplorer Lite | 6/1/2024 | 17/6/2026 | Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter. | |
| Modificada | Media (6.1) | 0.72% | — | Kodcloud Kodexplorer | 19/12/2023 | 17/6/2026 | Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php. | |
| Modificada | Crítica (9.8) | 0.70% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the file plugins/officeLive/app.php. The manipulation of the argument path leads to server-side request forgery. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/webodf/app.php. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… |