Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
–

9658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6)0.38%—Hermes WebuiAI13/5/202614/7/2026
Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted session with an unrestricted workspace value. Attackers can supply a blocked filesystem root in the workspace field and subsequently…
AplazadaMedia (6.1)0.25%—Fast-xml-builderAI13/5/202617/6/2026
fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.
AplazadaMedia (6.1)0.25%—Fast-xml-builderAI13/5/202617/6/2026
fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->...), allowing an attacker to break out of an XML comment and inject arbitrary…
AplazadaMedia (5.1)0.31%—Kuicms PHP EEAI13/5/202617/6/2026
Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoint. Attackers can send POST requests to /web/?c=bbs&a=reply with HTML and JavaScript payloads in the content parameter…
AplazadaAlta (7.5)0.46%—Theme-fusion Avada BuilderAI13/5/202617/6/2026
The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.5)0.46%💥 PoCTheme-fusion Avada BuilderAI13/5/202617/6/2026
The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaCrítica (9.3)0.73%—Guardianwall MailsuiteAIGuardianwall Mail Security CloudAI13/5/202617/6/2026
Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user…
AplazadaMedia (5.3)0.23%—Stylemixthemes Cost Calculator BuilderAI13/5/20267/10/2026
El plugin Cost Calculator Builder para WordPress es vulnerable a Manipulación de Precios No Autenticada y Referencia Directa Insegura a Objeto (IDOR) en todas las versiones hasta la 4.0.1, inclusive, solo cuando se usa en combinación con Cost Calculator Builder PRO. Esto se debe a que la acción AJAX…
AnalizadaMedia (6.1)0.27%—Kyverno Policy-reporter-ui12/5/202617/6/2026
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component uses v-html for the…
ModificadaCrítica (9.9)0.39%—Nginxui Nginx UI12/5/202617/6/2026
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to…
AnalizadaAlta (7.5)0.51%—Espressif Arduino-esp3212/5/202617/6/2026
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 computes the authentication hash using the URI field from the client's Authorization header, without verifying that…
AnalizadaCrítica (9.8)0.83%—Espressif Arduino-esp3212/5/202617/6/2026
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP header field…
AnalizadaAlta (8.5)0.11%—Intel Quickassist Technology12/5/202617/6/2026
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may…
AnalizadaAlta (8.5)0.11%—Intel Quickassist Technology12/5/202617/6/2026
Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may…
AnalizadaMedia (6.8)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (6.9)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (6.8)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via…
AnalizadaMedia (4.8)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur…
AnalizadaMedia (6.9)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via…
AnalizadaMedia (5.4)0.09%—Intel Connectivity Performance Suite12/5/202621/7/2026
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…
AnalizadaMedia (6.9)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
Pendiente de análisisAlta (8.5)0.11%—Intel Quickassist Adapter 8960 SoftwareAI12/5/202617/6/2026
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result…
AnalizadaMedia (6.9)0.10%—Intel Quickassist Technology12/5/202617/6/2026
Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaMedia (6.4)0.32%—Quick TableAI12/5/202617/6/2026
The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
Pendiente de análisisMedia (4.7)0.32%—Sapui5AI12/5/202617/6/2026
SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low impact on…