Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
512 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.60% | — | Webassembly Binary Toolkit | 2/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of… | |
| Aplazada | Alta (7.1) | 0.31% | — | Madfishdigital Bulk Noindex Nofollow ToolkitAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit bulk-noindex-nofollow-toolkit-by-mad-fish allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through <= 2.16. | |
| Aplazada | Media (5.3) | 0.36% | — | Inspry Agency-toolkitAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Agency Toolkit: from n/a through <= 1.0.24. | |
| Aplazada | Media (4.3) | 0.37% | — | Wpmessiah Swiss Toolkit FOR WPAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP swiss-toolkit-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Swiss Toolkit For WP: from n/a through <= 1.4.0. | |
| Aplazada | Media (4.3) | 0.30% | — | Wpmessiah Swiss Toolkit FOR WPAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Swiss Toolkit For WP swiss-toolkit-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Swiss Toolkit For WP: from n/a through <= 1.4.5. | |
| Aplazada | Crítica (9.1) | 1.3% | 💥 PoC | Themeegg ToolkitAI | 11/3/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Server.This issue affects ThemeEgg ToolKit: from n/a through <= 1.2.9. | |
| Aplazada | Media (6.4) | 0.26% | — | Templatesnext ToolkitAI | 1/3/2025 | 17/6/2026 | The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Baja (2.8) | 0.19% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (2.8) | 0.24% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause a NULL pointer exception by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the nvdisasm binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.26% | — | Nvidia Cuda Toolkit | 25/2/2025 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service. | |
| Aplazada | Alta (7.1) | 0.25% | — | Awcode ToolkitAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awcode AWcode Toolkit awcode-toolkit allows Reflected XSS.This issue affects AWcode Toolkit: from n/a through <= 1.0.14. | |
| Analizada | Media (5.4) | 0.20% | — | Intel AdvisorIntel Oneapi Base Toolkit | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (8.1) | 3.7% | — | Nvidia Container ToolkitNvidia GPU Operator | 12/2/2025 | 17/6/2026 | NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of… | |
| Analizada | Media (6.5) | 0.33% | — | Nvidia Container ToolkitNvidia GPU Operator | 28/1/2025 | 17/6/2026 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this… | |
| Analizada | Alta (8.4) | 0.67% | — | Nvidia Container ToolkitNvidia GPU Operator | 28/1/2025 | 17/6/2026 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of… | |
| Analizada | Alta (7.6) | 1.1% | — | Nvidia Container ToolkitNvidia GPU Operator | 28/1/2025 | 17/6/2026 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (6.5) | 0.23% | — | Kopatheme Kopa Nictitate ToolkitAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kopatheme Kopa Nictitate Toolkit kopa-nictitate-toolkit allows Stored XSS.This issue affects Kopa Nictitate Toolkit: from n/a through <= 1.0.2. | |
| Analizada | Alta (8.8) | 0.75% | — | Wpextended Ultimate Wordpress Toolkit | 8/1/2025 | 17/6/2026 | The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute… |