Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.34%—Adobe DNG Software Development KIT16/6/202628/8/2026
DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaMedia (5.5)0.26%—Adobe DNG Software Development KIT16/6/202628/8/2026
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (5.5)0.26%—Adobe DNG Software Development KIT16/6/202628/8/2026
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaMedia (5.5)0.26%—Adobe DNG Software Development KIT16/6/202628/8/2026
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AplazadaAlta (7.5)0.39%—Wpdeveloper EmbedpressAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
AplazadaAlta (7.5)0.43%—Wpdeveloper ReviewxAI15/6/202617/6/2026
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
AplazadaMedia (5.3)0.29%—Wpdeveloper Essential Addons FOR ElementorAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
AnalizadaAlta (7.5)0.46%—IBM Qiskit Software Development KIT12/6/202617/6/2026
IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion in the parser.
AnalizadaAlta (8.1)0.36%—Zoom Meeting Software Development KITZoom Workplace12/6/202617/6/2026
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaMedia (4.7)0.33%—Aqara Developer Portal12/6/20269/7/2026
The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of…
AnalizadaMedia (5.3)0.38%—Aqara Cloud Developer Portal12/6/202610/7/2026
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with…
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
AplazadaMedia (6.4)0.42%—Wpdeveloper EmbedpressAI6/6/202623/7/2026
The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (5.3)0.56%💥 PoCWpdeveloper Essential Addons FOR ElementorAI6/6/202623/7/2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_more function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated…
AplazadaAlta (7.2)0.26%—Wpdeveloper Essential BlocksAI5/6/202623/7/2026
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and…
AnalizadaAlta (8.5)0.12%—Codesys Development System26/5/202624/7/2026
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting…
AnalizadaAlta (8.5)0.14%—Codesys Development System26/5/202624/7/2026
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.
AplazadaMedia (6.5)0.31%—Wpdeveloper Essential Addons FOR ElementorAI14/5/202617/6/2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it…
AplazadaMedia (6.4)0.42%—Wpdeveloper Essential BlocksAI2/5/202617/6/2026
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and including, 6.0.4. This is due to…
AplazadaAlta (8.1)0.46%—Meware Software Development INC PdksAI30/4/202617/6/2026
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.
AplazadaAlta (8.1)0.39%—Meware Software Development INC PdksAI30/4/202617/6/2026
Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.
AplazadaMedia (6.5)0.39%—Meware Software Development INC PdksAI30/4/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.
AplazadaMedia (5.3)0.31%—Wpdeveloper BetterdocsAI29/4/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10.
AplazadaAlta (7.7)0.37%—Wpdeveloper TemplatelyAI27/4/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1.
AplazadaMedia (4.3)0.35%—Wpdeveloper BetterdocsAI24/4/202617/6/2026
The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for…