Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.32% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages. | |
| Analizada | Alta (8.6) | 0.49% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account. | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 30/9/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume. | |
| Aplazada | Alta (8.5) | 0.42% | — | Home-assistant Home AssistantAI | 14/10/2025 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field, which is then… | |
| Aplazada | Media (4.6) | 0.17% | — | HCL Unica Maxai AssistantAI | 12/10/2025 | 17/6/2026 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session. | |
| Analizada | Media (5.8) | 0.12% | — | HP Support Assistant | 1/10/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |
| Aplazada | Media (5.3) | 0.27% | — | Loopus WP Virtual AssistantAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0. | |
| Aplazada | Media (5.9) | 0.18% | — | Davidlingren Media Library AssistantAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.28. | |
| Aplazada | Alta (7.1) | 0.19% | — | Beaver Builder Wordpress AssistantAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Media (5.4) | 0.18% | — | Watson Assistant FOR IBM Cloud PAK FOR Data | 28/8/2025 | 26/9/2026 | IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (4.3) | 0.32% | — | Media Library AssistantAI | 19/8/2025 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3.27. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.53% | — | NextgenassistantAI | 15/8/2025 | 17/6/2026 | The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Alta (8.6) | 0.35% | — | Home-assistant Tapo ControlAI | 14/8/2025 | 17/6/2026 | HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself — it only impacts the GitHub Actions… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Driver AND Support Assistant ToolAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path element for some Intel(R) Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.1) | 0.15% | — | Motorola Software FIX Rescue AND Smart AssistantAI | 17/7/2025 | 17/6/2026 | A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software. | |
| Analizada | Media (5.4) | 0.31% | — | Davidlingren Media Library Assistant | 16/7/2025 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.8) | 0.12% | — | HP Support Assistant | 8/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion. | |
| Analizada | Media (5.4) | 0.23% | — | Akeles OUT OF Office Assistant | 3/7/2025 | 17/6/2026 | Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter. | |
| Analizada | Alta (7.1) | 0.13% | — | HP Support Assistant | 5/6/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |
| Aplazada | Media (6.2) | 0.08% | — | Transsion AivoiceassistantAI | 15/5/2025 | 17/6/2026 | Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage. | |
| Aplazada | Media (5.9) | 0.23% | — | Davidlingren Media Library AssistantAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.24. | |
| Analizada | Media (6.1) | 0.21% | — | Hliu Large Language AND Vision Assistant | 20/3/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of… |