Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.13% | — | NI Labview | 25/8/2026 | 8/9/2026 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions. | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (5.8) | 0.61% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab Origin ViewerAI | 20/8/2026 | 31/8/2026 | OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab Origin ViewerAI | 20/8/2026 | 31/8/2026 | OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.5) | 0.55% | — | Link Preview JSAI | 20/8/2026 | 18/9/2026 | Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final… | |
| Aplazada | Alta (7.2) | 0.27% | — | PDF Smart ViewerAI | 18/8/2026 | 20/8/2026 | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Geminilabs Site ReviewsAI | 18/8/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews allows Stored XSS.This issue affects Site Reviews: from n/a through 8.2.0. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Trueview T18061 Wifi 3MP Robot Pan-tilt Security CameraAI | 17/8/2026 | 31/8/2026 | An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component | |
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Aplazada | Alta (8.5) | 0.36% | — | ReviewerAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | |
| Aplazada | Media (5.3) | 0.44% | — | Keking KkfileviewAI | 11/8/2026 | 9/9/2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path parameter from FileController#getFiles to Files.newDirectoryStream without… | |
| Aplazada | Media (5.8) | 0.43% | — | Keking KkfileviewAI | 11/8/2026 | 9/9/2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in server/src/main/java/cn/keking/config/WebConfig.java, allowing FileConvertQueueTask to fetch an attacker-selected URL… | |
| Pendiente de análisis | Baja (2.1) | 0.60% | — | Phoenixframework Phoenix Live ViewAI | 10/8/2026 | 12/8/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a :to value containing ASCII tab, LF or CR. redirect/2 validates :to through the private validate_local_url!/2 in… | |
| Aplazada | Alta (8.8) | 0.54% | — | CheckviewAI | 10/8/2026 | 26/8/2026 | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated… | |
| Aplazada | Media (5.4) | 0.23% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin… | |
| Aplazada | Alta (8.1) | 0.39% | — | Contentviewspro Content ViewsAI | 7/8/2026 | 26/8/2026 | The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Purview Ediscovery | 7/8/2026 | 7/8/2026 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.19% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+8 | 6/8/2026 | 18/9/2026 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Media (5.5) | 0.16% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+8 | 6/8/2026 | 18/9/2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service | |
| Aplazada | Media (4.9) | 0.51% | — | Ljapps WP Tripadvisor Review SliderAI | 5/8/2026 | 12/8/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.55% | — | Advanced ViewsAI | 1/8/2026 | 12/8/2026 | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the register_rest_routes. This makes it possible for… |