Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.24% | — | Theupdateframework Go-tuf | 27/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file… | |
| Modificada | Alta (7.1) | 0.21% | — | Gitoxidelabs Gix-date | 26/1/2026 | 17/6/2026 | A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined behavior when these malformed strings are subsequently processed. This could… | |
| Analizada | Alta (7.5) | 0.22% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification… | |
| Analizada | Alta (7.5) | 0.59% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic… | |
| Aplazada | Alta (8.5) | 0.18% | — | Acer Updater ServiceAI | 16/1/2026 | 17/6/2026 | Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during… | |
| Aplazada | Alta (8.5) | 0.19% | — | Splashtop Software UpdaterAI | 13/1/2026 | 17/6/2026 | Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and… | |
| Aplazada | Media (5.3) | 0.21% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 30/12/2025 | 5/10/2026 | Missing Authorization vulnerability in tychesoftwares Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through <= 3.2.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 23/12/2025 | 17/6/2026 | Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0. | |
| Analizada | Crítica (9.3) | 1.2% | ⚠ Explotación activa | Asus Live Update | 17/12/2025 | 25/9/2026 | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions… | |
| Analizada | Baja (2.1) | 0.79% | — | Shenzhenningyuandatechnology Tc155 Firmware | 16/12/2025 | 17/6/2026 | A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The manipulation leads to improper access controls. The attack requires being on the local network. The exploit is publicly available and might… | |
| Analizada | Baja (2.1) | 0.64% | — | Shenzhenningyuandatechnology Tc155 Firmware | 16/12/2025 | 17/6/2026 | A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing manipulation of the argument FactoryDefault with the input Hard can lead to improper access controls. The attack requires access to… | |
| Analizada | Baja (2.1) | 0.71% | — | Shenzhenningyuandatechnology Tc155 Firmware | 16/12/2025 | 17/6/2026 | A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTSP Service. Performing manipulation results in denial of service. The attack must originate from the local network. The exploit has been made public and could be used. The vendor was contacted early… | |
| Analizada | Baja (2.1) | 0.88% | — | Shenzhenningyuandatechnology Tc155 Firmware | 16/12/2025 | 17/6/2026 | A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such manipulation leads to improper authentication. The attack must be carried out from within the local network. The exploit has been disclosed to the public and… | |
| Aplazada | Media (5.4) | 0.23% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.3.1. | |
| Aplazada | Media (5.4) | 0.10% | — | Intel ONE Boot Flash UpdateAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel ONE Boot Flash UpdateAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Server Configuration UtilityAIIntel Server Firmware Update UtilityAI | 11/11/2025 | 17/6/2026 | Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user… | |
| Analizada | Alta (7.3) | 0.28% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |
| Analizada | Alta (7.3) | 0.30% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. | |
| Aplazada | Baja (3.8) | 0.13% | — | Github Workflow UpdaterAIMicrosoft VS CodeAI | 28/10/2025 | 17/6/2026 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api. An attacker with… | |
| Aplazada | Media (6.5) | 0.20% | — | Konstantin Pankratov Date CounterAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Konstantin Pankratov Date counter date-counter allows Stored XSS.This issue affects Date counter: from n/a through <= 2.0.3. | |
| Aplazada | Media (4.3) | 0.25% | — | Joby Joseph SEO Meta Description UpdaterAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Joby Joseph SEO Meta Description Updater seo-meta-description-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Meta Description Updater: from n/a through <= 1.2.0. | |
| Aplazada | Alta (8.7) | 0.26% | — | Nedatec Consulting PrevengosAI | 25/9/2025 | 17/6/2026 | SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in… | |
| Aplazada | Media (4.3) | 0.14% | — | Mayo Moriyama Force Update TranslationsAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations force-update-translations allows Cross Site Request Forgery.This issue affects Force Update Translations: from n/a through <= 0.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Luke Mlsna Last-updated-shortcodeAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luke Mlsna Last Updated Shortcode last-updated-shortcode allows Stored XSS.This issue affects Last Updated Shortcode: from n/a through <= 1.0.1. |