Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.83% | — | Microsoft Dataverse | 13/5/2025 | 17/6/2026 | Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Crítica (9.8) | 3.7% | — | Microsoft Dataverse | 8/5/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.28% | — | Jegstudio Gutenverse | 29/4/2025 | 17/6/2026 | The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.1) | 0.36% | — | Zenverse Wordpress-theme-demo-barAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zenverse Theme Demo Bar wordpress-theme-demo-bar allows Reflected XSS.This issue affects Theme Demo Bar: from n/a through <= 1.6.3. | |
| Analizada | Alta (8.8) | 1.4% | — | Microsoft Dataverse | 21/3/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.2) | 0.76% | — | Microsoft Dataverse | 13/3/2025 | 17/6/2026 | Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.1) | 0.20% | — | ARM C1-premium FirmwareARM C1-pro FirmwareARM C1-ultra FirmwareARM Cortex-x3 Firmware+5 | 28/1/2025 | 17/6/2026 | An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced. | |
| Aplazada | Media (4.3) | 0.19% | — | Themes4wp Popularis VerseAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themes4wp Popularis Verse popularis-verse allows Cross Site Request Forgery.This issue affects Popularis Verse: from n/a through <= 1.1.1. | |
| Aplazada | Media (5.3) | 0.59% | — | Jegstudio GutenverseAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through 1.8.5. | |
| Analizada | Crítica (9.8) | 0.56% | — | ARM Cortex-a710 FirmwareARM Cortex-a77 FirmwareARM Cortex-a78 FirmwareARM Cortex-a78ae Firmware+12 | 10/12/2024 | 17/6/2026 | Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2… | |
| Aplazada | Crítica (10) | 0.54% | — | Stefan Bohacek Fediverse EmbedsAI | 2/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through <= 1.5.3. | |
| Modificada | Media (5.4) | 0.25% | — | Crossedcode Bverse Convert | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edwin Rivera bVerse Convert bverse-convert allows Stored XSS.This issue affects bVerse Convert: from n/a through <= 1.3.7.1. | |
| Analizada | Alta (8.8) | 0.75% | — | Microsoft Dataverse | 15/10/2024 | 17/6/2026 | Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.3) | 0.43% | — | Gouniverse Golang CMS | 8/9/2024 | 17/6/2026 | A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. The manipulation of the argument alias leads to cross site scripting. The attack can be initiated remotely. Upgrading to version… | |
| Analizada | Media (5.4) | 0.26% | — | Jegstudio Gutenverse | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.4. | |
| Modificada | Media (5.4) | 0.25% | — | Jegstudio Gutenverse | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.2. | |
| Analizada | Media (6.1) | 0.44% | — | Jegstudio Gutenverse | 3/5/2024 | 17/6/2026 | The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (5.3) | 0.36% | — | Nvidia Omniverse Launcher | 3/8/2023 | 17/6/2026 | NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability… | |
| Modificada | Media (5.4) | 0.39% | — | Hcltech Verse | 1/8/2023 | 17/6/2026 | HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. | |
| Modificada | Media (6.1) | 0.34% | — | Hcltech Verse | 26/7/2023 | 17/6/2026 | HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive… | |
| Modificada | Media (6.1) | 0.59% | — | Deothemes AmelaDeothemes ArendelleDeothemes EverseDeothemes Medikaid+1 | 18/7/2023 | 17/6/2026 | Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully… | |
| Modificada | Alta (7.5) | 2.2% | — | Microsoft YET Another Reverse Proxy | 23/6/2023 | 17/6/2026 | Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Reverse Proxy Auth | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. | |
| Modificada | Alta (7.5) | 0.28% | — | Rocketsoftware UnidataRocketsoftware Universe | 29/3/2023 | 17/6/2026 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. |