Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.32%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
AnalizadaAlta (8.6)0.49%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.
AnalizadaMedia (5.8)0.39%—RBI Restaurant Brands International Assistant17/10/202530/9/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.
AplazadaAlta (8.5)0.42%—Home-assistant Home AssistantAI14/10/202517/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field, which is then…
AplazadaMedia (4.6)0.17%—HCL Unica Maxai AssistantAI12/10/202517/6/2026
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.
AnalizadaMedia (5.8)0.12%—HP Support Assistant1/10/202517/6/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
AplazadaMedia (5.3)0.27%—Loopus WP Virtual AssistantAI26/9/202517/6/2026
Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0.
AplazadaMedia (5.9)0.18%—Davidlingren Media Library AssistantAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.28.
AplazadaAlta (7.1)0.19%—Beaver Builder Wordpress AssistantAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2.
AnalizadaBaja (3.3)0.11%—Samsung Sassistant3/9/202517/6/2026
Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
AnalizadaBaja (3.3)0.11%—Samsung Sassistant3/9/202517/6/2026
Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
AnalizadaBaja (3.3)0.11%—Samsung Sassistant3/9/202517/6/2026
Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.
AnalizadaMedia (5.4)0.18%—Watson Assistant FOR IBM Cloud PAK FOR Data28/8/202526/9/2026
IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaMedia (4.3)0.32%—Media Library AssistantAI19/8/202517/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3.27. This makes it possible for…
AplazadaAlta (7.5)0.53%—NextgenassistantAI15/8/202517/6/2026
The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete…
AplazadaAlta (8.6)0.35%—Home-assistant Tapo ControlAI14/8/202517/6/2026
HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself — it only impacts the GitHub Actions…
AplazadaMedia (5.4)0.13%—Intel Driver AND Support Assistant ToolAI12/8/202517/6/2026
Uncontrolled search path element for some Intel(R) Driver &amp; Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.1)0.15%—Motorola Software FIX Rescue AND Smart AssistantAI17/7/202517/6/2026
A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software.
AnalizadaMedia (5.4)0.31%—Davidlingren Media Library Assistant16/7/202517/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (5.8)0.12%—HP Support Assistant8/7/202517/6/2026
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion.
AnalizadaMedia (5.4)0.23%—Akeles OUT OF Office Assistant3/7/202517/6/2026
Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter.
AnalizadaAlta (7.1)0.13%—HP Support Assistant5/6/202517/6/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
AplazadaMedia (6.2)0.08%—Transsion AivoiceassistantAI15/5/202517/6/2026
Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.
AplazadaMedia (5.9)0.23%—Davidlingren Media Library AssistantAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.24.
AnalizadaMedia (6.1)0.21%—Hliu Large Language AND Vision Assistant20/3/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of…
Orbitaley — Vulnerabilidades