Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.53% | — | Machothemes CPO Companion | 30/1/2023 | 17/6/2026 | The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.4) | 0.57% | — | Extendthemes Mesmerize Companion | 16/1/2023 | 17/6/2026 | The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (4.8) | 0.54% | — | Machothemes CPO Companion | 10/1/2023 | 17/6/2026 | The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Baja (3.9) | 0.16% | — | Hcltech Traveler Companion | 25/10/2021 | 17/6/2026 | "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK" | |
| Modificada | Baja (3.9) | 0.23% | — | Hcltech Traveler Companion | 21/10/2021 | 17/6/2026 | "HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK" | |
| Modificada | Alta (7.2) | 1.7% | — | Atlassian Companion | 1/6/2020 | 17/6/2026 | The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure. | |
| Modificada | Alta (7.8) | 0.35% | — | Atlassian Companion | 1/6/2020 | 17/6/2026 | The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability. | |
| Modificada | Media (4.6) | 1.4% | — | Microsoft Your Phone Companion | 15/4/2020 | 17/6/2026 | An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notifications, aka 'Microsoft YourPhone Application for Android Authentication Bypass… | |
| Modificada | Alta (8.8) | 2.1% | 💥 PoC | Eaton UPS Companion | 23/3/2020 | 17/6/2026 | UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results… | |
| Modificada | Alta (8.8) | 0.67% | — | Codeermeneer Companion Sitemap Generator | 16/8/2019 | 17/6/2026 | The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 2.0% | — | Codeermeneer Companion Auto Update | 16/8/2019 | 17/6/2026 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. | |
| Modificada | Alta (8.8) | 0.65% | — | Codeermeneer Companion Auto Update | 16/8/2019 | 17/6/2026 | The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | |
| Modificada | Alta (7.5) | 1.8% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Notes Traveler Companion | 2/3/2015 | 17/6/2026 | The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a… | |
| Modificada | Media (5.4) | 2.7% | — | Microsoft Tech Companion | 9/9/2014 | 17/6/2026 | The Microsoft Tech Companion (aka com.technet) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 77% | 💥 Exploit | Dlink Dir505 Shareport Mobile Companion FirmwareDlink Dir505 Shareport Mobile CompanionDlink Dir505l Shareport Mobile Companion FirmwareDlink Dir-505l Shareport Mobile Companion+2 | 2/6/2014 | 17/6/2026 | Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a… | |
| Modificada | Alta (9.3) | 4.2% | — | Dlink Dir-826l Wireless N600 Cloud Router FirmwareDlink Dir-826l Wireless N600 Cloud RouterDlink Dir-505l Shareport Mobile Companion FirmwareDlink Dir-505l Shareport Mobile Companion | 12/5/2014 | 16/6/2026 | D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a direct request when an authorized session is active. | |
| Modificada | Media (6.8) | 3.2% | — | Nomachine NX WEB Companion | 19/9/2012 | 16/6/2026 | nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file. |