Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
3425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.25% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.1) | 0.26% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information. | |
| Analizada | Alta (7.8) | 0.28% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 29/7/2026 | 2/9/2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (8) | 0.40% | — | Teamviewer Full ClientAITeamviewer HostAI | 29/7/2026 | 30/7/2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host. | |
| Aplazada | Media (4.3) | 0.14% | — | Ljapps WP Google Review SliderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Ljapps WP Google Review SliderAI | 27/7/2026 | 27/7/2026 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Aplazada | Crítica (9.8) | 2.6% | — | Catalyst View WkhtmltopdfAIWkhtmltopdfAI | 25/7/2026 | 13/8/2026 | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Purview Data Governance | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.4) | 0.42% | — | Rich Showcase FOR Google ReviewsAI | 24/7/2026 | 24/7/2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.4) | 0.29% | — | ReviewerAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | |
| Aplazada | Crítica (9.9) | 0.79% | — | Advanced ViewsAI | 23/7/2026 | 23/7/2026 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Grid List View FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (4.8) | 0.13% | — | Smashballoon Reviews FeedAI | 20/7/2026 | 21/7/2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the… | |
| Analizada | Alta (8.7) | 0.45% | — | Viewcomponent View Component | 17/7/2026 | 29/7/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream… | |
| Analizada | Media (6.8) | 0.33% | — | Viewcomponent View Component | 17/7/2026 | 29/7/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render_in; if the same component, collection, or spacer component instance is reused across requests,… | |
| Aplazada | Media (4.9) | 0.48% | — | Ljapps WP Tripadvisor Review SliderAI | 16/7/2026 | 16/7/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.43% | 💥 PoC | Cusrev Customer Reviews FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist)… | |
| Aplazada | Media (6.5) | 0.52% | — | Caxperts Universalplantviewer Webservices ServerAI | 14/7/2026 | 15/7/2026 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver. | |
| Aplazada | Media (5.1) | 0.57% | — | Phoenixframework Phoenix Live ViewAI | 13/7/2026 | 13/7/2026 | Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2 functions in… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JET ReviewsAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Aman CF7 ViewsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views – Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views – Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2. | |
| Aplazada | Media (4.4) | 0.40% | — | Widgets FOR Google ReviewsAI | 11/7/2026 | 13/7/2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to… | |
| Aplazada | Media (6.4) | 0.42% | — | Cusrev Customer Reviews FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Interview Management SystemAI | 9/7/2026 | 9/7/2026 | A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… |