Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.34% | — | Adobe DNG Software Development KIT | 16/6/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.26% | — | Adobe DNG Software Development KIT | 16/6/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.26% | — | Adobe DNG Software Development KIT | 16/6/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.26% | — | Adobe DNG Software Development KIT | 16/6/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpdeveloper EmbedpressAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper ReviewxAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper Essential Addons FOR ElementorAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Qiskit Software Development KIT | 12/6/2026 | 17/6/2026 | IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion in the parser. | |
| Analizada | Alta (8.1) | 0.36% | — | Zoom Meeting Software Development KITZoom Workplace | 12/6/2026 | 17/6/2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Media (4.7) | 0.33% | — | Aqara Developer Portal | 12/6/2026 | 9/7/2026 | The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of… | |
| Analizada | Media (5.3) | 0.38% | — | Aqara Cloud Developer Portal | 12/6/2026 | 10/7/2026 | The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper EmbedpressAI | 6/6/2026 | 23/7/2026 | The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (5.3) | 0.56% | 💥 PoC | Wpdeveloper Essential Addons FOR ElementorAI | 6/6/2026 | 23/7/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.26% | — | Wpdeveloper Essential BlocksAI | 5/6/2026 | 23/7/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and… | |
| Analizada | Alta (8.5) | 0.12% | — | Codesys Development System | 26/5/2026 | 24/7/2026 | The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting… | |
| Analizada | Alta (8.5) | 0.14% | — | Codesys Development System | 26/5/2026 | 24/7/2026 | The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components. | |
| Aplazada | Media (6.5) | 0.31% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/5/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it… | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper Essential BlocksAI | 2/5/2026 | 17/6/2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and including, 6.0.4. This is due to… | |
| Aplazada | Alta (8.1) | 0.46% | — | Meware Software Development INC PdksAI | 30/4/2026 | 17/6/2026 | Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. | |
| Aplazada | Alta (8.1) | 0.39% | — | Meware Software Development INC PdksAI | 30/4/2026 | 17/6/2026 | Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. | |
| Aplazada | Media (6.5) | 0.39% | — | Meware Software Development INC PdksAI | 30/4/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpdeveloper BetterdocsAI | 29/4/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10. | |
| Aplazada | Alta (7.7) | 0.37% | — | Wpdeveloper TemplatelyAI | 27/4/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1. | |
| Aplazada | Media (4.3) | 0.35% | — | Wpdeveloper BetterdocsAI | 24/4/2026 | 17/6/2026 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for… |