Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.32. | |
| Analizada | Media (4.7) | 0.24% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operator to follow a crafted authorization URL could execute JavaScript in the… | |
| Analizada | Media (5.3) | 0.34% | — | Homeassistant-ai Home Assistant MCP Server | 11/3/2026 | 17/6/2026 | ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attacker can submit arbitrary URLs to perform internal network reconnaissance via an… | |
| Aplazada | Media (4.3) | 0.35% | — | Media Library AssistantAI | 5/3/2026 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Alta (8.8) | 0.78% | — | Music-assistant Music Assistant Server | 20/2/2026 | 17/6/2026 | Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API allows users to bypass the .m3u extension… | |
| Aplazada | Media (4.3) | 0.19% | — | Echoplugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0. | |
| Aplazada | Media (5.3) | 0.22% | — | Ays-chatgpt-assistantAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4. | |
| Aplazada | Alta (7) | 0.16% | — | Intel Quick Assist TechnologyAI | 10/2/2026 | 15/7/2026 | Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This… | |
| Aplazada | Media (6.8) | 0.10% | — | Intel Quick Assist TechnologyAI | 10/2/2026 | 17/6/2026 | Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… | |
| Analizada | Alta (7.8) | 0.10% | — | Dell Supportassist OS Recovery | 13/1/2026 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (5.5) | 0.11% | — | Dell Supportassist OS Recovery | 13/1/2026 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering. | |
| Analizada | Crítica (9.3) | 53% | 💥 PoC | Servicenow NOW Assist AI AgentsServicenow Virtual Agent API | 12/1/2026 | 17/6/2026 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances… | |
| Aplazada | Alta (7.1) | 0.25% | — | Loopus WP Virtual AssistantAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Stored XSS.This issue affects WP Virtual Assistant: from n/a through <= 3.1. | |
| Aplazada | Media (4.3) | 0.18% | — | Recorp Ai-content-writing-assistantAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One ai-content-writing-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, ChatGPT, Image… | |
| Aplazada | Media (5.3) | 0.27% | — | Bitapps BIT AssistAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/a through <= 1.5.11. | |
| Analizada | Media (4) | 0.40% | — | Home-assistant | 23/12/2025 | 17/6/2026 | Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability. | |
| Aplazada | Media (5.3) | 0.35% | — | Davidlingren Media Library AssistantAI | 9/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n/a through <= 3.29. | |
| Analizada | Media (5.4) | 0.08% | — | HP Image Assistant | 3/12/2025 | 17/6/2026 | — | |
| Aplazada | Alta (8.5) | 0.19% | — | Jumpcloud Remote AssistAI | 2/12/2025 | 17/6/2026 | JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent uninstall or update operations. The Remote Assist uninstaller performs privileged create, write, execute, and delete actions on predictable files… | |
| Aplazada | Media (4) | 0.12% | — | Samsung Cloud AssistantAI | 2/12/2025 | 25/9/2026 | Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access partial data in sandbox. | |
| Aplazada | Alta (7.2) | 0.93% | 💥 PoC | S2B AI AssistantAI | 21/11/2025 | 17/6/2026 | The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, with Editor-level… | |
| Analizada | Alta (7.3) | 0.13% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur… | |
| Analizada | Media (5.8) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when… | |
| Analizada | Media (6.8) | 0.12% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially… | |
| Analizada | Media (4.8) | 0.11% | — | Intel Quickassist Technology | 11/11/2025 | 17/6/2026 | Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local… |