Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 332 respecto a la semana anterior
Críticas / altas1275▼ 217 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.22% | — | Esri Portal FOR Arcgis | 29/9/2025 | 30/9/2026 | Existe una vulnerabilidad de scripting entre sitios reflejado en Esri Portal for ArcGIS 11.4 y versiones anteriores que podría permitir a un atacante remoto autenticado con acceso administrativo suministrar una cadena manipulada que ejecutaría código JavaScript arbitrario en el navegador. | |
| Aplazada | Baja (2) | 0.25% | — | Gstarsoft GstarcadAI | 29/9/2025 | 17/6/2026 | A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File Renaming Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Applying a patch is the… | |
| Modificada | Alta (7.5) | 0.52% | — | Algoliasearch-helper | 27/9/2025 | 17/6/2026 | Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected… | |
| Aplazada | Media (5.9) | 0.18% | — | Terryl SEO Search PermalinkAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. SEO Search Permalink seo-search-permalink allows Stored XSS.This issue affects SEO Search Permalink: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpo-hr NGG Smart Image SearchAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search: from n/a through <= 3.4.3. | |
| Aplazada | Media (6.5) | 0.28% | — | Search Atlas Group Search Atlas SEOAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Search Atlas Group Search Atlas SEO metasync allows Stored XSS.This issue affects Search Atlas SEO: from n/a through <= 2.5.4. | |
| Aplazada | Media (6.5) | 0.20% | — | Syedbalkhi Compact ArchivesAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Compact Archives compact-archives allows Stored XSS.This issue affects Compact Archives: from n/a through <= 4.1.0. | |
| Aplazada | Crítica (9.1) | 0.36% | — | StarchAI | 20/9/2025 | 17/6/2026 | Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with a counter, the epoch time, the built-in rand function, the PID, and internal Perl reference addresses. The PID will come from a small set of numbers, and the epoch time may be guessed, if… | |
| Aplazada | Media (6.3) | 0.25% | — | Saysis Computer Systems Trade Ltd. CO Starcities E-municipality ManagementAI | 19/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site Scripting (XSS). This issue affects StarCities E-Municipality Management: before 20250825. | |
| Modificada | Media (6.5) | 0.24% | — | Parceljs Parcel | 17/9/2025 | 17/6/2026 | npm parcel 2.0.0-alpha y anteriores tiene una vulnerabilidad de error de validación de origen. Sitios web maliciosos pueden enviar XMLHTTPRequests al servidor de desarrollo de la aplicación y leer la respuesta para robar código fuente cuando los desarrolladores los visitan. | |
| Aplazada | Media (5.4) | 0.13% | — | Hack Repair GUY Plugin ArchiverAI | 17/9/2025 | 25/9/2026 | El plugin Plugin Archiver de The Hack Repair Guy para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 2.0.4, inclusive. Esto se debe a la validación de nonce faltante o incorrecta en la función bulk_remove(). Esto hace posible que atacantes no autenticados realicen la eliminación… | |
| Analizada | Alta (7.8) | 0.17% | — | Autodesk Autocad Plant 3DAutodesk Advance SteelAutodesk Civil 3DAutodesk Autocad LT+7 | 16/9/2025 | 17/6/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.17% | — | Autodesk RevitAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 16/9/2025 | 17/6/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.2) | 0.73% | — | Hack Repair GUY Plugin ArchiverAI | 12/9/2025 | 17/6/2026 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the prepare_items function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (5.3) | 0.22% | — | Berqwp SearchproAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a through <= 2.2.53. | |
| Modificada | Alta (8.1) | 0.35% | 💥 PoC | Mezereon Smart Search AND Filter | 8/9/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter | |
| Analizada | Media (5.3) | 0.33% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 8/9/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU… | |
| Aplazada | Crítica (9.4) | 1.5% | — | InternetarchiveAI | 6/9/2025 | 17/6/2026 | internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.download() method does not properly sanitize user-supplied filenames or validate the… | |
| Aplazada | Media (5.9) | 0.18% | — | Thomas Harris Search Cloud ONEAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Search Cloud One search-cloud-one allows Stored XSS.This issue affects Search Cloud One: from n/a through <= 2.2.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Marcshowpass ShowpassAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marcshowpass Showpass WordPress Extension showpass allows Stored XSS.This issue affects Showpass WordPress Extension: from n/a through <= 4.0.3. | |
| Aplazada | Media (5.9) | 0.22% | — | Webvitaly Search BY GoogleAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Search by Google search-google allows Stored XSS.This issue affects Search by Google: from n/a through <= 1.9. | |
| Aplazada | Media (6.5) | 0.21% | — | Eric Mann WP Publication ArchiveAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Mann WP Publication Archive wp-publication-archive allows Stored XSS.This issue affects WP Publication Archive : from n/a through <= 3.0.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Barn2 Plugins Posts Table With Search AND SortAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Barn2 Plugins Posts Table with Search & Sort posts-data-table allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Table with Search & Sort: from n/a through <= 1.4.10. | |
| Aplazada | Media (6.9) | 0.07% | — | Learningcircuit Local Deep ResearchAI | 3/9/2025 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given… | |
| Aplazada | Alta (7.1) | 0.17% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 31/8/2025 | 26/9/2026 | Vulnerabilidad de falta de autorización en UkrSolution Barcode Scanner with Inventory & Order Manager. Este problema afecta a Barcode Scanner with Inventory & Order Manager: desde n/a hasta 1.5.3. |