Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1970 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5)0.18%—Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI6/4/202517/6/2026
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access…
AplazadaAlta (7.1)0.37%—Mbyte Explore PagesAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mbyte Explore pages explore-pages allows Reflected XSS.This issue affects Explore pages: from n/a through <= 1.01.
AplazadaAlta (7.1)0.14%—Blightly ExplorerAI24/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0.
AnalizadaMedia (6.5)0.55%—Dhtmlx File Explorer7/2/202517/6/2026
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.
AnalizadaMedia (6.5)0.75%—Dhtmlx File Explorer7/2/202517/6/2026
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.
AplazadaAlta (7.1)0.19%—Campusexplorer WidgetAI7/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through <= 1.1.
AplazadaMedia (6.5)0.33%—Tailored Media Tailored ToolsAI2/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tailored Media Tailored Tools tailored-tools allows Stored XSS.This issue affects Tailored Tools: from n/a through <= 1.8.4.
ModificadaMedia (4.9)0.52%—Bowo Code Explorer30/10/202417/6/2026
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress…
ModificadaMedia (6.1)0.29%—Campusexplorer Widget29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CampusExplorer Campus Explorer Widget campus-explorer-widget allows Reflected XSS.This issue affects Campus Explorer Widget: from n/a through <= 1.4.
AplazadaAlta (7.5)0.52%—Lorex Technology INC LorexpingAI14/10/202417/6/2026
An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.
AplazadaMedia (6.1)0.26%—Splunk Config ExplorerAI27/5/202417/6/2026
Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
AplazadaMedia (4.2)0.27%—Sysinternals Process ExplorerAI7/5/202417/6/2026
Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.
AplazadaMedia (6.1)0.39%—Amazon Aws-js-s3-explorerAI11/3/202417/6/2026
Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html.
ModificadaMedia (5.5)0.30%—Nsasoft Product KEY Explorer21/1/202417/6/2026
A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit…
ModificadaAlta (7.8)0.19%—Explorerplusplus Explorer++17/1/202417/6/2026
Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler (SEH) records.
ModificadaAlta (7.8)0.26%—Fit2cloud Cloudexplorer Lite6/1/202417/6/2026
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.
ModificadaMedia (6.1)0.72%—Kodcloud Kodexplorer19/12/202317/6/2026
Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php.
ModificadaCrítica (9.8)0.70%—Kodcloud Kodexplorer16/12/202317/6/2026
A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the file plugins/officeLive/app.php. The manipulation of the argument path leads to server-side request forgery. The attack can be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.76%—Kodcloud Kodexplorer16/12/202317/6/2026
A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/webodf/app.php. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.91%—Kodcloud Kodexplorer16/12/202317/6/2026
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the file plugins/zipView/app.php of the component ZIP Archive Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.84%—Kodcloud Kodexplorer16/12/202317/6/2026
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the file /index.php?pluginApp/to/yzOffice/getFile of the component API Endpoint Handler. The manipulation of the argument path/file leads to unrestricted upload. The attack can…
ModificadaMedia (6.1)0.40%—Extplorer14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaCrítica (9.8)0.61%—Fit2cloud Cloudexplorer Lite30/10/202317/6/2026
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue.
ModificadaAlta (7.5)0.43%—Fit2cloud Cloudexplorer Lite20/9/202317/6/2026
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.