Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.37% | — | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS ApplicationAI | 4/3/2025 | 17/6/2026 | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history,… | |
| Aplazada | Media (5.5) | 0.19% | — | Tencent Technology Beijing Company Limited Tencent Microvision IOSAI | 27/2/2025 | 17/6/2026 | An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (5.5) | 0.19% | — | Merchants Union Consumer Finance Company Limited Merchants Union Finance IOSAI | 27/2/2025 | 17/6/2026 | An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Analizada | Media (5.4) | 0.35% | — | Unlimited-elements Unlimited Elements FOR Elementor | 20/2/2025 | 17/6/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Boardroom Limited Dividend Distribution TAX Election SystemAI | 18/2/2025 | 17/6/2026 | A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input. | |
| Aplazada | Alta (7.3) | 0.43% | — | Lexmark International XCAILexmark International CSAIMitel CXAI | 13/2/2025 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user. | |
| Aplazada | Alta (7.3) | 1.2% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could… | |
| Aplazada | Alta (8.8) | 0.59% | — | Mitel Openscape 4000AIMitel Openscape 4000 ManagerAI | 6/2/2025 | 17/6/2026 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute… | |
| Aplazada | Media (4.8) | 0.16% | — | Apphousekitchen Aldente Charge LimiterAI | 6/2/2025 | 17/6/2026 | A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper of the component XPC Service. The manipulation leads to improper authorization.… | |
| Aplazada | Alta (7.1) | 0.17% | — | Ederson Peka Unlimited Page SidebarsAI | 3/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ederson Peka Unlimited Page Sidebars unlimited-page-sidebars allows Stored XSS.This issue affects Unlimited Page Sidebars: from n/a through <= 0.2.6. | |
| Aplazada | Media (4.3) | 0.43% | — | Unlimited Theme Addon FOR Elementor AND WoocommerceAI | 11/1/2025 | 17/6/2026 | The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'uta-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.31% | — | Unlimited-elements Unlimited Elements FOR Elementor | 9/1/2025 | 17/6/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.135 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.41% | — | Amentotech Private Limited WpguppyAIAmentotech Private Limited Wpguppy LiteAI | 7/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalation.This issue affects WPGuppy: from n/a through <= 1.1.0. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Amenotech Private Limited WpguppyAI | 7/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Softclever Limited User ReferralAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftClever Limited User Referral user-referral-free allows Reflected XSS.This issue affects User Referral: from n/a through <= 8.0. | |
| Analizada | Media (5.4) | 0.35% | — | Unlimited-elements Unlimited Elements FOR Elementor | 12/12/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Baja (2.7) | 38% | ⚠ Explotación activa💥 Exploit | Mitel Micollab | 10/12/2024 | 4/8/2026 | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the… | |
| Aplazada | Alta (7.5) | 0.42% | — | Butterfly Effect Limited Monica Chatgpt AI AssistantAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Aplazada | Alta (7.5) | 0.42% | — | Butterfly Effect Limited Monica Your AI CopilotAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Analizada | Media (6.5) | 0.36% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A successful exploit could allow an attacker to perform a phishing… | |
| Analizada | Alta (8.8) | 1.3% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insufficient parameter sanitization. A successful exploit could allow… | |
| Analizada | Crítica (9.1) | 98% | ⚠ Explotación activa💥 Exploit | Mitel Micollab | 21/10/2024 | 4/8/2026 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view,… | |
| Analizada | Media (6.6) | 0.55% | — | Mitel Micollab | 21/10/2024 | 17/6/2026 | A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary commands on the system within the context of… | |
| Analizada | Media (5.6) | 0.77% | 💥 PoC | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary… | |
| Analizada | Crítica (9.8) | 1.8% | — | Mitel MicollabMitel Mivoice Business Solution Virtual Instance | 21/10/2024 | 17/6/2026 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and… |