Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 7/1/2026 | 17/6/2026 | Insecure Temporary File vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1. | |
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 7/1/2026 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1. | |
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 7/1/2026 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1. | |
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 7/1/2026 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1. | |
| Aplazada | Media (4.9) | 0.17% | — | Bdthemes Prime SliderAI | 24/12/2025 | 7/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request Forgery.This issue affects Prime Slider – Addons For Elementor: from n/a through <= 4.0.10. | |
| Aplazada | Media (4.3) | 0.29% | — | Bdthemes Prime SliderAI | 18/12/2025 | 17/6/2026 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.9 via the import_elementor_template AJAX action. This makes it possible for authenticated attackers, with subscriber level access and above, to make web requests to… | |
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 12/12/2025 | 17/6/2026 | The System Console Utility for Windows is vulnerable to a DLL planting vulnerability | |
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 11/12/2025 | 17/6/2026 | A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. | |
| Analizada | Media (5.4) | 0.11% | — | Intel Quartus Prime | 11/12/2025 | 17/6/2026 | A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. | |
| Analizada | Media (5.4) | 0.10% | — | Intel Quartus Prime | 11/12/2025 | 17/6/2026 | Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists. | |
| Aplazada | Media (4.3) | 0.26% | — | Metagauss EventprimeAI | 9/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.4.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Metagauss EventprimeAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.4.1. | |
| Aplazada | Media (4.3) | 0.22% | — | EventprimeAI | 8/11/2025 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on the 'booking_add_notes' function in all versions up to, and including, 4.2.0.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists… | |
| Analizada | Media (6.5) | 0.32% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system. | |
| Analizada | Media (6.5) | 0.42% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 20/8/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. This vulnerability is due to… | |
| Aplazada | Alta (7.1) | 0.24% | — | Primersoftware Primer Mydata FOR WoocommerceAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Reflected XSS.This issue affects Primer MyData for Woocommerce: from n/a through <= 4.2.5. | |
| Analizada | Media (4.3) | 0.34% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 16/7/2025 | 29/6/2026 | A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker… | |
| Analizada | Alta (7.2) | 71% | 💥 Exploit | SqliteApple IpadosApple Iphone OSApple Macos+5 | 15/7/2025 | 26/6/2026 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. | |
| Modificada | Media (6.4) | 0.30% | — | Metagauss Eventprime | 15/5/2025 | 17/6/2026 | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. | |
| Aplazada | Alta (7.8) | 0.22% | — | Avira PrimeAI | 9/5/2025 | 17/6/2026 | Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU… | |
| Aplazada | Alta (7.8) | 0.22% | — | Avira PrimeAI | 9/5/2025 | 17/6/2026 | Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attackers to gain system-level privileges via arbitrary file deletion | |
| Analizada | Media (4.8) | 0.29% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 2/4/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. The vulnerability exists… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 2/4/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is… | |
| Aplazada | Alta (7.1) | 0.31% | — | Primersoftware Primer Mydata FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Reflected XSS.This issue affects Primer MyData for Woocommerce: from n/a through < 4.2.4. |