Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.2)0.19%—Artificial Intelligence Project Artificial Intelligence10/7/202616/7/2026
Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
AnalizadaBaja (3.3)0.21%—Artificial Intelligence Project Artificial Intelligence10/7/202616/7/2026
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
AnalizadaMedia (6.1)0.25%—Artificial Intelligence Project Artificial Intelligence10/7/20266/8/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
AplazadaAlta (7.5)0.63%—Artifex Jbig2AI9/7/202614/9/2026
An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaMedia (6.5)0.33%—Artisanworkshop Japanized FOR WoocommerceAI29/6/202629/6/2026
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
AnalizadaAlta (7.1)0.58%—Artifex Mupdf23/6/20266/10/2026
MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in…
AplazadaAlta (7.1)0.16%—Im-magic Partition ResizerAIIm-magic MDA NtdrvAI21/6/202622/6/2026
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be…
AplazadaAlta (7.1)0.16%—Easeus Partition MasterAI21/6/202623/6/2026
A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and…
AplazadaAlta (7.1)0.16%—Easeus Partition MasterAI21/6/202622/6/2026
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be…
AplazadaAlta (7.1)0.16%—Aomei Partition AssistantAI21/6/202622/6/2026
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may…
AnalizadaAlta (8.7)0.66%—Artio Book IT!19/6/202621/8/2026
Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer,…
AnalizadaAlta (8.7)0.73%—Image-sizeRedhat DiscoveryRedhat GatekeeperRedhat Trusted Artifact Signer+19/6/202624/7/2026
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by…
AplazadaAlta (7.2)0.32%—Martin Helmich HbookAI27/5/202617/6/2026
The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaAlta (8.2)0.50%💥 PoCDate Menu OF News ArticlesAI19/5/202617/6/2026
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the…
AplazadaCrítica (9.3)0.43%—Creartia IcmsAI18/5/202617/6/2026
Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling privilege escalation without the need for credentials.
AnalizadaAlta (7.6)0.38%—Artica Pandora FMS12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.1)0.42%—Artica Pandora FMS12/5/202617/6/2026
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.6)0.36%—Artica Pandora FMS12/5/202617/6/2026
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (7.1)0.18%—Artica Pandora FMS12/5/202617/6/2026
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
AnalizadaCrítica (9.1)0.48%—Artica Pandora FMS12/5/202617/6/2026
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
ModificadaBaja (1.9)0.19%—Artifex Mupdf28/4/202617/6/2026
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be…
AplazadaMedia (5.5)0.59%—Duartium Papers-mcp-serverAI28/4/202624/7/2026
A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the file src/main.py. Such manipulation of the argument topic leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be…
AnalizadaMedia (4.8)0.19%—Artifex Mupdf16/4/202617/6/2026
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling…
AnalizadaAlta (7.5)1.7%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800
AnalizadaAlta (8.7)0.44%—Artica Pandora FMS13/4/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 777 through 800
Orbitaley — Vulnerabilidades