Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.34% | — | Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+2 | 3/3/2025 | 17/6/2026 | Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits. | |
| Analizada | Media (5.6) | 0.32% | — | Kashipara Online Attendance Management System | 14/2/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter. | |
| Aplazada | Media (6.5) | 0.23% | — | Mkkmail Aparat ResponsiveAI | 13/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive aparat-responsive allows DOM-Based XSS.This issue affects Aparat Responsive: from n/a through <= 1.3. | |
| Analizada | Alta (7.8) | 0.41% | — | Parallels Remote Application ServerParallels | 5/2/2025 | 17/6/2026 | Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order… | |
| Analizada | Media (6.3) | 0.24% | — | Paragraphs Table Project Paragraphs Table | 9/1/2025 | 21/7/2026 | Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2. | |
| Aplazada | Alta (7.1) | 0.32% | — | Maheshwaghmare MG Parallax SliderAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Waghmare MG Parallax Slider mg-parallax-slider allows Reflected XSS.This issue affects MG Parallax Slider: from n/a through <= 1.0.. | |
| Aplazada | Alta (7.8) | 0.21% | — | Sunix Parallel DriverAI | 7/1/2025 | 17/6/2026 | A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These… | |
| Analizada | Alta (7.3) | 0.18% | — | Siemens ParasolidSiemens Solid Edge Se2024Siemens Solid Edge Se2025 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow… | |
| Aplazada | Media (4.3) | 0.56% | — | Paypal Brasil Para WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in PayPal PayPal Brasil para WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Brasil para WooCommerce: from n/a through 1.4.2. | |
| Analizada | Media (4.3) | 0.80% | — | Jenkins Filesystem List Parameter | 27/11/2024 | 17/6/2026 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system. | |
| Aplazada | Media (6.5) | 0.39% | — | Digitalzoomstudio ParallaxerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Parallaxer parallaxer-lite-parallax-effects-on-images allows Stored XSS.This issue affects Parallaxer: from n/a through <= 1.00. | |
| Aplazada | Media (6.4) | 0.37% | — | Duckdiverllc Parallax ImageAI | 19/11/2024 | 17/6/2026 | The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.25% | — | Masterbip Para ElementorAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masterbip MasterBip para Elementor masterbip-for-elementor allows DOM-Based XSS.This issue affects MasterBip para Elementor: from n/a through <= 1.6.3. | |
| Modificada | Media (6.1) | 0.29% | — | Unizoewebsolutions Jlayer Parallax Slider | 20/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unizoe Web Solutions jLayer Parallax Slider jlayer-parallax-slider-wp allows Reflected XSS.This issue affects jLayer Parallax Slider: from n/a through <= 1.0. | |
| Analizada | Media (5.4) | 0.42% | — | Duckdiverllc Parallax Image | 17/10/2024 | 17/6/2026 | The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortcode in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 1.00% | — | Parallels DesktopAI | 23/9/2024 | 17/6/2026 | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root. | |
| Analizada | Media (5.4) | 0.30% | — | Cryoutcreations Parabola | 15/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through 2.4.1. | |
| Analizada | Alta (7.5) | 0.41% | — | Thisfunctional CTT Expresso Para Woocommerce | 1/8/2024 | 17/6/2026 | The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly accessible and contain sensitive information such as sender and receiver names,… | |
| Modificada | Crítica (10) | 0.32% | — | Parallels Desktop | 21/6/2024 | 17/6/2026 | Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add malicious code in a script and populate the BASH_ENV environment variable with the path to the malicious script, executing on application startup. An attacker could exploit this… | |
| Modificada | Media (6.7) | 0.25% | — | Parallels Desktop | 20/6/2024 | 17/6/2026 | Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order… | |
| Modificada | Alta (7.8) | 0.29% | — | Parallels Desktop | 20/6/2024 | 17/6/2026 | Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order… | |
| Aplazada | Media (6.8) | 0.34% | — | Paradox Ip150 Internet ModuleAI | 19/6/2024 | 17/6/2026 | The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system. | |
| Modificada | Crítica (9.8) | 0.49% | — | HPE Cray Parallel Application Launch Service | 13/6/2024 | 17/6/2026 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | |
| Analizada | Media (4.8) | 0.24% | — | Siemens Jt2goSiemens ParasolidSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain a null pointer dereference… | |
| Analizada | Alta (7.3) | 0.26% | — | Siemens Jt2goSiemens ParasolidSiemens Teamcenter Visualization | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain an out of bounds read past the… |