Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1970 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5) | 0.18% | — | Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI | 6/4/2025 | 17/6/2026 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access… | |
| Aplazada | Alta (7.1) | 0.37% | — | Mbyte Explore PagesAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mbyte Explore pages explore-pages allows Reflected XSS.This issue affects Explore pages: from n/a through <= 1.01. | |
| Aplazada | Alta (7.1) | 0.14% | — | Blightly ExplorerAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer: from n/a through <= 2.3.0. | |
| Analizada | Media (6.5) | 0.55% | — | Dhtmlx File Explorer | 7/2/2025 | 17/6/2026 | Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality. | |
| Analizada | Media (6.5) | 0.75% | — | Dhtmlx File Explorer | 7/2/2025 | 17/6/2026 | Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function. | |
| Aplazada | Alta (7.1) | 0.19% | — | Campusexplorer WidgetAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Tailored Media Tailored ToolsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tailored Media Tailored Tools tailored-tools allows Stored XSS.This issue affects Tailored Tools: from n/a through <= 1.8.4. | |
| Modificada | Media (4.9) | 0.52% | — | Bowo Code Explorer | 30/10/2024 | 17/6/2026 | The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress… | |
| Modificada | Media (6.1) | 0.29% | — | Campusexplorer Widget | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CampusExplorer Campus Explorer Widget campus-explorer-widget allows Reflected XSS.This issue affects Campus Explorer Widget: from n/a through <= 1.4. | |
| Aplazada | Alta (7.5) | 0.52% | — | Lorex Technology INC LorexpingAI | 14/10/2024 | 17/6/2026 | An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Aplazada | Media (6.1) | 0.26% | — | Splunk Config ExplorerAI | 27/5/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product. | |
| Aplazada | Media (4.2) | 0.27% | — | Sysinternals Process ExplorerAI | 7/5/2024 | 17/6/2026 | Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling. | |
| Aplazada | Media (6.1) | 0.39% | — | Amazon Aws-js-s3-explorerAI | 11/3/2024 | 17/6/2026 | Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html. | |
| Modificada | Media (5.5) | 0.30% | — | Nsasoft Product KEY Explorer | 21/1/2024 | 17/6/2026 | A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit… | |
| Modificada | Alta (7.8) | 0.19% | — | Explorerplusplus Explorer++ | 17/1/2024 | 17/6/2026 | Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler (SEH) records. | |
| Modificada | Alta (7.8) | 0.26% | — | Fit2cloud Cloudexplorer Lite | 6/1/2024 | 17/6/2026 | Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter. | |
| Modificada | Media (6.1) | 0.72% | — | Kodcloud Kodexplorer | 19/12/2023 | 17/6/2026 | Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and escalate privileges via the APP_HOST parameter at config/i18n/en/main.php. | |
| Modificada | Crítica (9.8) | 0.70% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in kalcaddle KodExplorer up to 4.51.03. Affected by this vulnerability is the function index of the file plugins/officeLive/app.php. The manipulation of the argument path leads to server-side request forgery. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.76% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in kalcaddle KodExplorer up to 4.51.03. Affected is an unknown function of the file plugins/webodf/app.php. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.91% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the file plugins/zipView/app.php of the component ZIP Archive Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.84% | — | Kodcloud Kodexplorer | 16/12/2023 | 17/6/2026 | A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the file /index.php?pluginApp/to/yzOffice/getFile of the component API Endpoint Handler. The manipulation of the argument path/file leads to unrestricted upload. The attack can… | |
| Modificada | Media (6.1) | 0.40% | — | Extplorer | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Extplorer component for Joomla. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Crítica (9.8) | 0.61% | — | Fit2cloud Cloudexplorer Lite | 30/10/2023 | 17/6/2026 | CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue. | |
| Modificada | Alta (7.5) | 0.43% | — | Fit2cloud Cloudexplorer Lite | 20/9/2023 | 17/6/2026 | An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. |