Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1895 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.26% | — | Zohocorp Asset ExplorerAIZohocorp Servicedesk PlusAIZohocorp Servicedesk Plus MSPAIZohocorp Supportcenter PlusAI | 20/8/2025 | 17/6/2026 | There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions… | |
| Aplazada | Media (4.3) | 0.24% | — | Runzero ExplorerAIBrotherAI | 12/8/2025 | 17/6/2026 | By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described by CVE-2024-51978 to calculate the default administrator… | |
| Modificada | Baja (2.1) | 0.40% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade the affected component. The action taken… | |
| Modificada | Baja (2.9) | 0.59% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack… | |
| Modificada | Baja (2.1) | 0.29% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue.… | |
| Aplazada | Media (5.1) | 0.65% | — | Ready File ExplorerAI | 16/4/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file. | |
| Aplazada | Media (5) | 0.18% | — | Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI | 6/4/2025 | 17/6/2026 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access… | |
| Aplazada | Alta (7.1) | 0.14% | — | Blightly ExplorerAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0. | |
| Analizada | Media (6.5) | 0.55% | — | Dhtmlx File Explorer | 7/2/2025 | 17/6/2026 | Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality. | |
| Analizada | Media (6.5) | 0.75% | — | Dhtmlx File Explorer | 7/2/2025 | 17/6/2026 | Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function. | |
| Aplazada | Alta (7.1) | 0.19% | — | Campusexplorer WidgetAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through <= 1.1. | |
| Modificada | Media (4.9) | 0.52% | — | Bowo Code Explorer | 30/10/2024 | 17/6/2026 | The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress… | |
| Modificada | Media (6.1) | 0.29% | — | Campusexplorer Widget | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CampusExplorer Campus Explorer Widget campus-explorer-widget allows Reflected XSS.This issue affects Campus Explorer Widget: from n/a through <= 1.4. | |
| Aplazada | Media (6.1) | 0.26% | — | Splunk Config ExplorerAI | 27/5/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product. | |
| Aplazada | Media (4.2) | 0.27% | — | Sysinternals Process ExplorerAI | 7/5/2024 | 17/6/2026 | Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling. | |
| Aplazada | Media (6.1) | 0.39% | — | Amazon Aws-js-s3-explorerAI | 11/3/2024 | 17/6/2026 | Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html. | |
| Modificada | Media (5.5) | 0.30% | — | Nsasoft Product KEY Explorer | 21/1/2024 | 17/6/2026 | A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit… | |
| Modificada | Alta (7.8) | 0.19% | — | Explorerplusplus Explorer++ | 17/1/2024 | 17/6/2026 | Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler (SEH) records. | |
| Modificada | Alta (7.8) | 0.26% | — | Fit2cloud Cloudexplorer Lite | 6/1/2024 | 17/6/2026 | Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter. | |
| Modificada | Media (6.1) | 0.72% | — | Kodcloud Kodexplorer | 19/12/2023 | 17/6/2026 | Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php. | |
| Modificada | Crítica (9.8) | 0.70% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the file plugins/officeLive/app.php. The manipulation of the argument path leads to server-side request forgery. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/webodf/app.php. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.91% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the file plugins/zipView/app.php of the component ZIP Archive Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.84% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the file /index.php?pluginApp/to/yzOffice/getFile of the component API Endpoint Handler. The manipulation of the argument path/file leads to unrestricted upload. The attack can… | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… |