Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.37%—Maharashtra State Electricity Distribution Company Limited Mahavitran IOS ApplicationAI4/3/202517/6/2026
Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history,…
AplazadaMedia (5.5)0.19%—Tencent Technology Beijing Company Limited Tencent Microvision IOSAI27/2/202517/6/2026
An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (5.5)0.19%—Merchants Union Consumer Finance Company Limited Merchants Union Finance IOSAI27/2/202517/6/2026
An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link.
AnalizadaMedia (5.4)0.35%—Unlimited-elements Unlimited Elements FOR Elementor20/2/202517/6/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaCrítica (9.8)0.51%—Boardroom Limited Dividend Distribution TAX Election SystemAI18/2/202517/6/2026
A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.
AplazadaAlta (7.3)0.43%—Lexmark International XCAILexmark International CSAIMitel CXAI13/2/202517/6/2026
Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
AplazadaAlta (7.3)1.2%—Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI6/2/202517/6/2026
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could…
AplazadaAlta (8.8)0.59%—Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI6/2/202517/6/2026
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute…
AplazadaMedia (4.8)0.16%—Apphousekitchen Aldente Charge LimiterAI6/2/202517/6/2026
A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper of the component XPC Service. The manipulation leads to improper authorization.…
AplazadaAlta (7.1)0.17%—Ederson Peka Unlimited Page SidebarsAI3/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ederson Peka Unlimited Page Sidebars unlimited-page-sidebars allows Stored XSS.This issue affects Unlimited Page Sidebars: from n/a through <= 0.2.6.
AplazadaMedia (4.3)0.43%—Unlimited Theme Addon FOR Elementor AND WoocommerceAI11/1/202517/6/2026
The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'uta-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.31%—Unlimited-elements Unlimited Elements FOR Elementor9/1/202517/6/2026
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.8)0.41%—Amentotech Private Limited WpguppyAIAmentotech Private Limited Wpguppy LiteAI7/1/202517/6/2026
Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalation.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaCrítica (9.8)0.51%—Amenotech Private Limited WpguppyAI7/1/202517/6/2026
Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaAlta (7.1)0.26%—Softclever Limited User ReferralAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftClever Limited User Referral user-referral-free allows Reflected XSS.This issue affects User Referral: from n/a through <= 8.0.
AnalizadaMedia (5.4)0.35%—Unlimited-elements Unlimited Elements FOR Elementor12/12/202417/6/2026
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaBaja (2.7)38%⚠ Explotación activa💥 ExploitMitel Micollab10/12/20244/8/2026
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the…
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Chatgpt AI AssistantAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Your AI CopilotAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AnalizadaMedia (6.5)0.36%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A successful exploit could allow an attacker to perform a phishing…
AnalizadaAlta (8.8)1.3%—Mitel MicollabMitel Mivoice Business Solution Virtual Instance21/10/202417/6/2026
A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insufficient parameter sanitization. A successful exploit could allow…
AnalizadaCrítica (9.1)98%⚠ Explotación activa💥 ExploitMitel Micollab21/10/20244/8/2026
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view,…
AnalizadaMedia (6.6)0.55%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary commands on the system within the context of…
AnalizadaMedia (5.6)0.77%💥 PoCMitel MicollabMitel Mivoice Business Solution Virtual Instance21/10/202417/6/2026
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary…
AnalizadaCrítica (9.8)1.8%—Mitel MicollabMitel Mivoice Business Solution Virtual Instance21/10/202417/6/2026
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and…