Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

3425 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.25%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+729/7/20262/9/2026
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
AnalizadaAlta (7.1)0.26%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+729/7/20262/9/2026
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
AnalizadaAlta (7.8)0.28%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+729/7/20262/9/2026
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AplazadaAlta (8)0.40%—Teamviewer Full ClientAITeamviewer HostAI29/7/202630/7/2026
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.
AplazadaMedia (4.3)0.14%—Ljapps WP Google Review SliderAI27/7/202627/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
AplazadaAlta (7.6)0.38%—Ljapps WP Google Review SliderAI27/7/202627/7/2026
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
AplazadaAlta (7.2)0.27%—3dflipbook PDF Viewer AND EmbedderAI27/7/202627/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
AplazadaCrítica (9.8)2.6%—Catalyst View WkhtmltopdfAIWkhtmltopdfAI25/7/202613/8/2026
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation…
AnalizadaCrítica (10)0.90%—Microsoft Purview Data Governance24/7/202629/7/2026
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (6.4)0.42%—Rich Showcase FOR Google ReviewsAI24/7/202624/7/2026
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (5.4)0.29%—ReviewerAI23/7/202623/7/2026
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
AplazadaCrítica (9.9)0.79%—Advanced ViewsAI23/7/202623/7/2026
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
AplazadaMedia (6.4)0.33%—Grid List View FOR WoocommerceAI23/7/202623/7/2026
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (4.8)0.13%—Smashballoon Reviews FeedAI20/7/202621/7/2026
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the…
AnalizadaAlta (8.7)0.45%—Viewcomponent View Component17/7/202629/7/2026
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the escaping behavior applied to normal #call return values. This creates an XSS risk when downstream…
AnalizadaMedia (6.8)0.33%—Viewcomponent View Component17/7/202629/7/2026
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render_in; if the same component, collection, or spacer component instance is reused across requests,…
AplazadaMedia (4.9)0.48%—Ljapps WP Tripadvisor Review SliderAI16/7/202616/7/2026
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.5)0.43%💥 PoCCusrev Customer Reviews FOR WoocommerceAI16/7/202616/7/2026
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist)…
AplazadaMedia (6.5)0.52%—Caxperts Universalplantviewer Webservices ServerAI14/7/202615/7/2026
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
AplazadaMedia (5.1)0.57%—Phoenixframework Phoenix Live ViewAI13/7/202613/7/2026
Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and Phoenix.LiveView.Utils.valid_live_navigation_destination!/2 functions in…
AplazadaMedia (5.3)0.33%—Crocoblock JET ReviewsAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
AplazadaAlta (7.1)0.25%—Aman CF7 ViewsAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views &#8211; Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2.
AplazadaMedia (4.4)0.40%—Widgets FOR Google ReviewsAI11/7/202613/7/2026
The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to…
AplazadaMedia (6.4)0.42%—Cusrev Customer Reviews FOR WoocommerceAI9/7/20269/7/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (5.5)0.43%—Code-projects Interview Management SystemAI9/7/20269/7/2026
A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be…