Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.71% | — | Parall Jspdf | 26/8/2025 | 17/6/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful PNG file that results in… | |
| Aplazada | Alta (7.7) | 0.17% | — | Paramount Macrium ReflectAI | 4/8/2025 | 17/6/2026 | Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx backup file and a malicious VSSSvr.dll located in the same directory. When a user with administrative privileges mounts a backup by opening the .mrimgx file, Reflect loads… | |
| Aplazada | Alta (7.7) | 0.15% | — | Paramount Macrium ReflectAI | 4/8/2025 | 17/6/2026 | Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proceeds to mount it,… | |
| Aplazada | Media (6.5) | 0.21% | — | Parakoos Image WallAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall image-wall allows Stored XSS.This issue affects Image Wall: from n/a through <= 3.1. | |
| Modificada | Alta (8.2) | 0.64% | — | Jenkins GIT Parameter | 9/7/2025 | 17/6/2026 | Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters. | |
| Analizada | Media (5.4) | 0.22% | — | Paragraphs Table Project Paragraphs Table | 26/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs table allows Cross-Site Scripting (XSS).This issue affects Paragraphs table: from 2.0.0 before 2.0.5. | |
| Aplazada | Crítica (9.3) | 0.42% | — | Facturaone Ticketbai Facturas Para WoocommerceAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Blind SQL Injection.This issue affects TicketBAI Facturas para WooCommerce: from n/a through <= 3.19. | |
| Aplazada | Media (5.4) | 0.32% | — | DE Paragon NO Spam AT ALLAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in De paragon No Spam At All no-spam-at-all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects No Spam At All: from n/a through <= 1.3. | |
| Aplazada | Media (5.4) | 0.32% | — | Facturaone Ticketbai Facturas Para WoocommerceAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TicketBAI Facturas para WooCommerce: from n/a through <= 3.45. | |
| Analizada | Alta (8.8) | 1.1% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege escalation. | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard link, an attacker can write to an arbitrary file, potentially… | |
| Analizada | Alta (7.8) | 0.28% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of… | |
| Analizada | Alta (7.8) | 0.32% | — | Parallels Desktop | 3/6/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine is restored, the prl_vmarchiver tool decompresses the file and writes the content back to its original location using root… | |
| Aplazada | Media (6.2) | 0.17% | — | ParaAI | 2/6/2025 | 17/6/2026 | Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging… | |
| Analizada | Media (4.8) | 0.31% | — | Thisfunctional CTT Expresso Para Woocommerce | 15/5/2025 | 17/6/2026 | The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Crítica (9.8) | 0.40% | — | Kashipara Billing SoftwareAI | 13/5/2025 | 17/6/2026 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Aplazada | Alta (7.1) | 0.31% | — | Parakoos Image WallAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall image-wall allows Reflected XSS.This issue affects Image Wall: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Ramanparashar UseinfluenceAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence useinfluence allows Stored XSS.This issue affects Useinfluence: from n/a through <= 1.0.8. | |
| Aplazada | Media (5.9) | 0.28% | — | Wp-maverick WP Parallax Content SliderAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp-maverick WP Parallax Content Slider wp-parallax-content-slider allows Stored XSS.This issue affects WP Parallax Content Slider: from n/a through <= 0.9.8. | |
| Analizada | Alta (8.7) | 0.69% | — | Parall Jspdf | 18/3/2025 | 17/6/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitised image urls to the addImage method, a user can provide a harmful data-url that results in high CPU… | |
| Aplazada | Alta (7.8) | 0.12% | — | Parallels DesktopAI | 16/3/2025 | 17/6/2026 | Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine. | |
| Analizada | Alta (7.8) | 0.34% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service. | |
| Analizada | Alta (7.8) | 0.50% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation. | |
| Analizada | Media (5.1) | 0.35% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation. | |
| Analizada | Alta (8.4) | 0.37% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine. |