Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
511 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Uncannyowl Uncanny Toolkit FOR LearndashAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.3. | |
| Aplazada | Media (5.4) | 0.13% | — | Century ToolkitAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Theme Century Century ToolKit century-toolkit allows Cross Site Request Forgery.This issue affects Century ToolKit: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.7) | 0.14% | — | Seagate ToolkitAI | 14/8/2025 | 17/6/2026 | The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a malicious Program.exe file, which would… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Oneapi ToolkitAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.5) | 0.12% | — | Codesys Runtime ToolkitAI | 4/8/2025 | 17/6/2026 | CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions. | |
| Aplazada | Alta (8.8) | 0.39% | — | Aapanel WP ToolkitAI | 18/7/2025 | 17/6/2026 | The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and gain full admin… | |
| Aplazada | Alta (8.5) | 0.83% | — | Nvidia Container ToolkitAI | 17/7/2025 | 17/6/2026 | NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service. | |
| Aplazada | Crítica (9) | 3.2% | 💥 PoC | Nvidia Container ToolkitAI | 17/7/2025 | 17/6/2026 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and… | |
| Aplazada | Media (5.3) | 0.41% | — | Actions ToolkitAI | 9/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. | |
| Analizada | Alta (7.8) | 0.30% | 💥 PoC | Nvidia Cuda Toolkit | 27/5/2025 | 17/6/2026 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a malformed ELF file. A successful exploit of this vulnerability might lead to arbitrary code… | |
| Aplazada | Alta (7.1) | 0.14% | — | Awcode-toolkitAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit awcode-toolkit allows Stored XSS.This issue affects AWcode Toolkit: from n/a through <= 1.0.18. | |
| Aplazada | Media (6.5) | 0.20% | — | Uncannyowl Uncanny Toolkit FOR LearndashAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.2. | |
| Aplazada | Media (6.4) | 0.23% | — | BON ToolkitAI | 15/5/2025 | 17/6/2026 | The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.15% | — | Intel AdvisorIntel Oneapi Base Toolkit | 13/5/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM 4769 Developers Toolkit | 12/5/2025 | 17/6/2026 | IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due to improper memory allocation of an excessive size. | |
| Aplazada | Alta (7.2) | 0.88% | — | WpmastertoolkitAI | 24/4/2025 | 17/6/2026 | The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents of arbitrary files on the server, which… | |
| Modificada | Alta (8.8) | 0.17% | — | Servit Affiliate-toolkit | 22/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This issue affects affiliate-toolkit: from n/a through <= 3.7.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Themefic Travelfic-toolkitAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Stored XSS.This issue affects Travelfic Toolkit: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Uncannyowl Uncanny Toolkit FOR LearndashAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.1. | |
| Analizada | Media (5.5) | 0.25% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.25% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe XMP Toolkit Software Development KIT | 8/4/2025 | 17/6/2026 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Baja (2.3) | 0.60% | — | Webassembly Binary Toolkit | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of… |