Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.6) | 0.17% | — | Arista EOSAI | 14/11/2025 | 17/6/2026 | On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153 | |
| Aplazada | Media (4.3) | 0.19% | — | Check PlagiarismAI | 24/10/2025 | 17/6/2026 | The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the chk_plag_mine_plugin_wpse10500_admin_action() function in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Modificada | Media (5.5) | 0.15% | — | Oracle Solaris | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require… | |
| Analizada | Media (6.5) | 0.15% | — | Oracle Solaris | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in… | |
| Aplazada | Media (6.5) | 0.26% | — | Arista Aos-8 InstantAIArista AOS 10AI | 14/10/2025 | 17/6/2026 | A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality. | |
| Analizada | Alta (7.8) | 0.22% | — | Oxinst Imaris Viewer | 2/9/2025 | 17/6/2026 | Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oxford Instruments Imaris Viewer. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.23% | — | Oxinst Imaris Viewer | 2/9/2025 | 17/6/2026 | Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oxford Instruments Imaris Viewer. User interaction is required to exploit this vulnerability in that the target… | |
| Aplazada | Alta (7.5) | 0.42% | — | Arista EOSAI | 25/8/2025 | 17/6/2026 | On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of authentication. | |
| Aplazada | Baja (3.8) | 0.10% | — | Arista EOSAI | 25/8/2025 | 17/6/2026 | On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol specific passwords… | |
| Aplazada | Alta (7.1) | 0.23% | — | Redqteam Alike - Wordpress Custom Post ComparisonAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Alike - WordPress Custom Post Comparison alike allows Reflected XSS.This issue affects Alike - WordPress Custom Post Comparison: from n/a through <= 3.0.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Arisoft Contact Form 7 Editor ButtonAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft Contact Form 7 Editor Button cf7-editor-button allows Reflected XSS.This issue affects Contact Form 7 Editor Button: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Parisneo LollmsAI | 7/7/2025 | 17/6/2026 | The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within the `lollms_authentication.py` file. This vulnerability allows attackers to enumerate valid usernames and guess passwords incrementally by analyzing response time differences. The affected version is… | |
| Modificada | Media (6.1) | 0.27% | — | Miliaris Amygdala | 17/6/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload. | |
| Modificada | Media (6.1) | 0.27% | — | Miliaris Amygdala | 17/6/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload. | |
| Modificada | Media (6.1) | 0.27% | — | Miliaris Amygdala | 17/6/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload. | |
| Aplazada | Baja (2.6) | 0.52% | — | Arista EOSAI | 27/5/2025 | 17/6/2026 | n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or… | |
| Aplazada | Media (5.3) | 0.19% | — | Arista EOSAI | 27/5/2025 | 17/6/2026 | On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this… | |
| Aplazada | Media (6.5) | 0.26% | — | Arista EOSAI | 27/5/2025 | 17/6/2026 | On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. | |
| Aplazada | Alta (7.5) | 0.59% | — | Arista EOSAI | 8/5/2025 | 17/6/2026 | On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in… | |
| Aplazada | Crítica (10) | 0.66% | — | Arista CloudvisionAI | 8/5/2025 | 17/6/2026 | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision… | |
| Aplazada | Alta (8.7) | 0.63% | — | Arista Cloudvision PortalAI | 8/5/2025 | 17/6/2026 | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Arista EOSAI | 8/5/2025 | 17/6/2026 | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear. | |
| Aplazada | Crítica (10) | 0.78% | — | Arista Cloudvision PortalAI | 8/5/2025 | 17/6/2026 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service. | |
| Aplazada | Media (6.5) | 0.28% | — | Arista EOSAI | 7/5/2025 | 17/6/2026 | On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc). | |
| Aplazada | Media (6.5) | 0.22% | — | Haris Zulfiqar TooltipAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haris Zulfiqar Tooltip wp-tooltip allows DOM-Based XSS.This issue affects Tooltip: from n/a through <= 1.0.1. |