Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.31% | — | Parisneo LollmsAI | 20/3/2025 | 17/6/2026 | A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit this by sending a… | |
| Aplazada | Alta (8.4) | 0.46% | — | Parisneo LollmsAI | 20/3/2025 | 17/6/2026 | A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This… | |
| Aplazada | Alta (8) | 0.23% | — | Parisneo LollmsAI | 20/3/2025 | 17/6/2026 | A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and… | |
| Aplazada | Alta (8.7) | 0.56% | — | Siemens Simatic PCS NEOAISiemens Simocode ESAISiemens Sirius Safety ESAISiemens Sirius Soft Starter ESAI+1 | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES… | |
| Analizada | Media (6.1) | 0.58% | 💥 Exploit | Neoloki WP Dream Carousel | 4/2/2025 | 17/6/2026 | The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (6.1) | 0.23% | — | Teamcal NEOAI | 31/1/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in TeamCal Neo, version 3.8.2. This allows an attacker to execute malicious JavaScript code, after injecting code via the ‘abs’ parameter in ‘/teamcal/src/index.php’. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Teamcal NEOAI | 31/1/2025 | 17/6/2026 | SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the ‘abs’ parameter in ‘/teamcal/src/index.php’. | |
| Analizada | Media (5.1) | 0.20% | — | ARM C1-premium FirmwareARM C1-pro FirmwareARM C1-ultra FirmwareARM Cortex-x3 Firmware+5 | 28/1/2025 | 17/6/2026 | An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced. | |
| Analizada | Media (6.5) | 0.41% | — | Neofix Simple Downloads List | 24/1/2025 | 17/6/2026 | The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofix_sdl' shortcode in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (8.5) | 0.40% | — | Vertim Neon Product DesignerAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0. | |
| Analizada | Alta (8.2) | 1.1% | 💥 PoC | Cs-grp NEO ImpactGreenware GreenguardHowyar SysreturnRadix Smart Recovery+3 | 14/1/2025 | 17/6/2026 | Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path. | |
| Analizada | Media (5.5) | 0.37% | — | NeovimVIMNetapp Bootstrap OS | 13/1/2025 | 17/6/2026 | When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before opening… | |
| Aplazada | Crítica (9.3) | 1.5% | — | Siemens Opcenter Execution FoundationAISiemens Opcenter IntelligenceAISiemens Opcenter QualityAISiemens Opcenter RdnlAI+3 | 16/12/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),… | |
| Analizada | Crítica (9.8) | 0.56% | — | ARM Cortex-a710 FirmwareARM Cortex-a77 FirmwareARM Cortex-a78 FirmwareARM Cortex-a78ae Firmware+12 | 10/12/2024 | 17/6/2026 | Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2… | |
| Aplazada | Media (6.5) | 0.35% | — | Mudssar Amazing NEO Icon Font FOR ElementorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mudssar amazing neo icon font for elementor amazing-neo-icon-font-for-elementor allows DOM-Based XSS.This issue affects amazing neo icon font for elementor: from n/a through <= 2.0.1. | |
| Modificada | Media (5.3) | 0.30% | — | MuttNeomuttRedhat Enterprise Linux | 12/11/2024 | 26/6/2026 | In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. | |
| Modificada | Media (5.3) | 0.33% | — | MuttNeomuttRedhat Enterprise Linux | 12/11/2024 | 26/6/2026 | In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender. | |
| Modificada | Media (5.9) | 0.33% | — | MuttNeomuttRedhat Enterprise Linux | 12/11/2024 | 26/6/2026 | In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Siemens Opcenter QualityAISiemens Opcenter RdnlAISiemens Simatic PCS NEOAISiemens Sinec NMSAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client… | |
| Analizada | Media (4.7) | 0.35% | — | Netapp Bootstrap OSNeovimVIM | 16/8/2024 | 17/6/2026 | The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window… | |
| Analizada | Media (4.2) | 0.33% | — | Netapp HCI Compute NodeNeovimVIM | 1/8/2024 | 17/9/2026 | Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However,… | |
| Aplazada | Alta (7.3) | 0.27% | — | Parisneo LollmsAI | 20/7/2024 | 17/6/2026 | A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders. | |
| Aplazada | Alta (8.5) | 0.23% | — | Siemens Simatic PCS NEOAISiemens Simatic Step 7AI | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-controllable input. This… | |
| Aplazada | Alta (7.3) | 0.52% | — | Parisneo LollmsAI | 27/6/2024 | 17/6/2026 | A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file`… | |
| Aplazada | Alta (7.4) | 0.45% | — | Parisneo LollmsAI | 27/6/2024 | 17/6/2026 | A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as `force_accept_remote_access` and `turn_on_code_validation`. |