Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

538 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.71%—Parall Jspdf26/8/202517/6/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful PNG file that results in…
AplazadaAlta (7.7)0.17%—Paramount Macrium ReflectAI4/8/202517/6/2026
Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx backup file and a malicious VSSSvr.dll located in the same directory. When a user with administrative privileges mounts a backup by opening the .mrimgx file, Reflect loads…
AplazadaAlta (7.7)0.15%—Paramount Macrium ReflectAI4/8/202517/6/2026
Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proceeds to mount it,…
AplazadaMedia (6.5)0.21%—Parakoos Image WallAI16/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall image-wall allows Stored XSS.This issue affects Image Wall: from n/a through <= 3.1.
ModificadaAlta (8.2)0.64%—Jenkins GIT Parameter9/7/202517/6/2026
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.
AnalizadaMedia (5.4)0.22%—Paragraphs Table Project Paragraphs Table26/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs table allows Cross-Site Scripting (XSS).This issue affects Paragraphs table: from 2.0.0 before 2.0.5.
AplazadaCrítica (9.3)0.42%—Facturaone Ticketbai Facturas Para WoocommerceAI9/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Blind SQL Injection.This issue affects TicketBAI Facturas para WooCommerce: from n/a through <= 3.19.
AplazadaMedia (5.4)0.32%—DE Paragon NO Spam AT ALLAI6/6/202517/6/2026
Missing Authorization vulnerability in De paragon No Spam At All no-spam-at-all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects No Spam At All: from n/a through <= 1.3.
AplazadaMedia (5.4)0.32%—Facturaone Ticketbai Facturas Para WoocommerceAI6/6/202517/6/2026
Missing Authorization vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TicketBAI Facturas para WooCommerce: from n/a through <= 3.45.
AnalizadaAlta (8.8)1.1%—Parallels Desktop3/6/202517/6/2026
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation.
AnalizadaAlta (7.8)0.32%—Parallels Desktop3/6/202517/6/2026
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially…
AnalizadaAlta (7.8)0.28%—Parallels Desktop3/6/202517/6/2026
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of…
AnalizadaAlta (7.8)0.32%—Parallels Desktop3/6/202517/6/2026
A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to its original location using root…
AplazadaMedia (6.2)0.17%—ParaAI2/6/202517/6/2026
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging…
AnalizadaMedia (4.8)0.31%—Thisfunctional CTT Expresso Para Woocommerce15/5/202517/6/2026
The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaCrítica (9.8)0.40%—Kashipara Billing SoftwareAI13/5/202517/6/2026
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.
AplazadaAlta (7.1)0.31%—Parakoos Image WallAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall image-wall allows Reflected XSS.This issue affects Image Wall: from n/a through <= 3.0.
AplazadaAlta (7.1)0.24%—Ramanparashar UseinfluenceAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence useinfluence allows Stored XSS.This issue affects Useinfluence: from n/a through <= 1.0.8.
AplazadaMedia (5.9)0.28%—Wp-maverick WP Parallax Content SliderAI24/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp-maverick WP Parallax Content Slider wp-parallax-content-slider allows Stored XSS.This issue affects WP Parallax Content Slider: from n/a through <= 0.9.8.
AnalizadaAlta (8.7)0.69%—Parall Jspdf18/3/202517/6/2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitised image urls to the addImage method, a user can provide a harmful data-url that results in high CPU…
AplazadaAlta (7.8)0.12%—Parallels DesktopAI16/3/202517/6/2026
Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine.
AnalizadaAlta (7.8)0.34%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
AnalizadaAlta (7.8)0.50%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
AnalizadaMedia (5.1)0.35%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
AnalizadaAlta (8.4)0.37%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.