Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.86%—Hliu Large Language AND Vision Assistant20/3/202517/6/2026
A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server…
AnalizadaAlta (7.5)0.69%—Hliu Large Language AND Vision Assistant20/3/202517/6/2026
A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path…
AplazadaAlta (7.2)0.70%—Beaver Builder Wordpress AssistantAI3/3/202517/6/2026
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
AplazadaAlta (7)0.25%—AiohttpAIAiohttp SessionAIHome-assistant Home Assistant CoreAI18/2/202517/6/2026
Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the past, `aiohttp-session`/`request` had the…
AnalizadaMedia (6.1)0.37%—Davidlingren Media Library Assistant4/1/202517/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaMedia (5.9)0.35%—Watson Assistant FOR IBM Cloud PAK FOR Data26/11/202417/6/2026
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.
AnalizadaMedia (5.4)0.16%—Intel Driver & Support Assistant13/11/202417/6/2026
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Driver & Support Assistant13/11/202417/6/2026
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7)0.17%—Intel Endpoint Management Assistant13/11/202417/6/2026
Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.1)0.21%—Grafana Labs GrafanaAIGrafana Labs Grafana Cloud Migration AssistantAI13/11/202417/6/2026
A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate…
AplazadaMedia (4)0.19%—Callassistant AI Call Assistant ScreenerAI7/11/202417/6/2026
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.
ModificadaAlta (7.2)1.1%—Davidlingren Media Library Assistant4/11/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.
AplazadaMedia (4.3)0.28%—Sovrn Editorial AssistantAI26/10/202417/6/2026
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.1)0.56%—Fusion Chat Chat AI Assistant ASK ME AnythingAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Chatgpt AI AssistantAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaCrítica (9.8)0.50%—Transsion AivoiceassistantAI16/10/202417/6/2026
Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.
AnalizadaMedia (5.5)0.14%—Samsung Sound Assistant8/10/202417/6/2026
Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.
AnalizadaAlta (7.5)0.85%💥 ExploitAys-pro Chatgpt Assistant27/9/202417/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and…
ModificadaAlta (7.5)0.30%—Ays-pro Chatgpt Assistant27/9/202417/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
AplazadaMedia (4)0.31%—10web AI AssistantAI26/9/202417/6/2026
Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or…
AplazadaAlta (8.8)0.57%—Gladys AssistantAI21/9/202417/6/2026
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
AnalizadaMedia (4.3)0.34%—Samsung Assistant4/9/202417/6/2026
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.
AnalizadaAlta (8.8)1.3%—Davidlingren Media Library Assistant13/8/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to…
ModificadaMedia (6.1)0.36%—Davidlingren Media Library Assistant2/7/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)0.58%—Davidlingren Media Library Assistant20/6/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
Orbitaley — Vulnerabilidades