Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.17% | — | HCL Unica Maxai AssistantAI | 12/10/2025 | 17/6/2026 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session. | |
| Aplazada | Media (6.3) | 0.26% | — | Gainsight AssistAI | 2/10/2025 | 17/6/2026 | Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. Assist allows Excavation, Authentication Bypass. This issue affects Assist: through 10.02.2025. | |
| Analizada | Media (5.8) | 0.12% | — | HP Support Assistant | 1/10/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |
| Aplazada | Media (5.3) | 0.27% | — | Loopus WP Virtual AssistantAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0. | |
| Aplazada | Media (5.9) | 0.18% | — | Davidlingren Media Library AssistantAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.28. | |
| Aplazada | Alta (7.1) | 0.19% | — | Beaver Builder Wordpress AssistantAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Sassistant | 3/9/2025 | 17/6/2026 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information. | |
| Analizada | Media (5.4) | 0.18% | — | Watson Assistant FOR IBM Cloud PAK FOR Data | 28/8/2025 | 26/9/2026 | IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (4.3) | 0.32% | — | Media Library AssistantAI | 19/8/2025 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3.27. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.53% | — | NextgenassistantAI | 15/8/2025 | 17/6/2026 | The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Alta (8.6) | 0.35% | — | Home-assistant Tapo ControlAI | 14/8/2025 | 17/6/2026 | HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself — it only impacts the GitHub Actions… | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Supportassist FOR Home PCS | 14/8/2025 | 17/6/2026 | SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 14/8/2025 | 17/6/2026 | SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | |
| Analizada | Alta (7.8) | 0.10% | — | Dell Supportassist FOR Business PCS | 14/8/2025 | 17/6/2026 | SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |
| Analizada | Alta (7.5) | 0.81% | 💥 PoC | Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+1 | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Driver AND Support Assistant ToolAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path element for some Intel(R) Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.8) | 0.14% | — | Intel Quickassist Technology | 12/8/2025 | 17/6/2026 | Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Supportassist OS Recovery | 6/8/2025 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Baja (2.4) | 0.18% | — | Dell Supportassist OS Recovery | 6/8/2025 | 17/6/2026 | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Aplazada | Alta (7.1) | 0.16% | — | Motorola Software FIX Rescue AND Smart AssistantAI | 17/7/2025 | 17/6/2026 | A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software. | |
| Analizada | Media (5.4) | 0.31% | — | Davidlingren Media Library Assistant | 16/7/2025 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.8) | 0.12% | — | HP Support Assistant | 8/7/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion. | |
| Analizada | Media (5.4) | 0.23% | — | Akeles OUT OF Office Assistant | 3/7/2025 | 17/6/2026 | Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter. |