Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
253 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.26% | — | Electronjs Electron | 4/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via… | |
| Analizada | Media (5.4) | 0.18% | — | Electronjs Electron | 4/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler. An app whose… | |
| Aplazada | Media (5.5) | 0.80% | — | Unigroup Electronic Archives SystemAI | 8/3/2026 | 17/6/2026 | A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly available and might… | |
| Analizada | Media (5.5) | 0.70% | — | Unigroup Electronic Archives System | 19/2/2026 | 17/6/2026 | A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.70% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an unknown function of the file /Using/Subject/downLoad.html. Performing a manipulation of the argument path results in path traversal. The attack may be initiated remotely. The exploit has been made… | |
| Analizada | Baja (2.1) | 0.51% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.75% | — | Unigroup Electronic Archives System | 18/2/2026 | 17/6/2026 | A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/Subject/downLoad. Performing a manipulation of the argument path results in path traversal. The attack is possible to be carried out… | |
| Aplazada | Media (5.3) | 0.39% | — | Shenzhen Zhibotong Electronics ZBT We2001AI | 11/2/2026 | 17/6/2026 | A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted session cookie value. | |
| Aplazada | Alta (8.1) | 0.26% | — | Shenzhen Zhibotong Electronics ZBT We2001AI | 11/2/2026 | 17/6/2026 | A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the parameters expected… | |
| Aplazada | Media (6.5) | 0.32% | — | Shenzhen Zhibotong Electronics ZBT We2001AI | 11/2/2026 | 17/6/2026 | A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device configuration data,… | |
| Aplazada | Crítica (10) | 0.75% | — | Shenzhen Zhibotong Electronics ZBT We2001AI | 11/2/2026 | 17/6/2026 | A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value. | |
| Aplazada | Media (5.4) | 0.10% | — | Electronhub AI PlaygroundAI | 10/2/2026 | 17/6/2026 | Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Aplazada | Alta (8.8) | 0.38% | — | Karel Electronics Industry AND Trade ViportAI | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects ViPort: through 23012026. | |
| Aplazada | Media (6.5) | 0.35% | — | Ninetheme ElectronAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Inim Electronics Smartliving SmartlanAI | 8/1/2026 | 17/6/2026 | INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models. | |
| Aplazada | Alta (7.8) | 0.16% | — | Tradingview DesktopAIElectronAI | 23/12/2025 | 17/6/2026 | TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Media (6.1) | 0.29% | 💥 PoC | Clincapture Captivate Electronic Data Capture | 22/12/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser. | |
| Aplazada | Media (4.3) | 0.22% | — | IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI | 10/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers. This issue affects DijiDemi: through 28.11.2025. | |
| Aplazada | Alta (8.6) | 0.18% | — | TAX Service Electronic HDMAI | 26/11/2025 | 17/6/2026 | The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements | |
| Aplazada | Crítica (9.8) | 0.33% | — | Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119. | |
| Aplazada | Crítica (10) | 0.36% | — | Deepseaelectronics Dse855AI | 31/10/2025 | 17/6/2026 | Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device. | |
| Aplazada | Alta (7.5) | 0.35% | — | CBK Soft Software Hardware Electronic Computer Systems Industry AND Trade INC EnvisionAI | 24/10/2025 | 17/6/2026 | Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting. This issue affects enVision: before… | |
| Aplazada | Media (5.5) | 0.17% | — | VHS Electronic Software ACE CenterAI | 20/10/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255. | |
| Aplazada | Media (6.1) | 0.27% | — | ElectronAI | 4/9/2025 | 17/6/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the… | |
| Aplazada | Media (5.9) | 0.16% | — | Delta Electronics DiaviewAI | 1/9/2025 | 17/6/2026 | Delta Electronics DIAView has an authentication bypass vulnerability. |