Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.51%—Markparticle Webserver21/4/202517/6/2026
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file code/http/httprequest.cpp of the component Registration. The manipulation of the argument username/password leads to sql injection. The attack may be launched…
AnalizadaMedia (6.9)0.70%—Markparticle Webserver21/4/202517/6/2026
A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulnerability is the function Buffer::HasWritten of the file code/buffer/buffer.cpp. The manipulation of the argument writePos_ leads to buffer overflow. The attack can be launched remotely. The exploit…
AplazadaCrítica (9.8)0.57%💥 PoCAdeptAIGithub Actions Upload ArtifactAI21/4/202517/6/2026
Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's…
AplazadaCrítica (9.3)0.65%—Lisandro Martinez Wp-smart-contractsAI11/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: from n/a through <= 2.0.12.
AplazadaCrítica (9.1)0.43%—Insert OR Embed Articulate Content Into WordpressAI10/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress insert-or-embed-articulate-content-into-wordpress allows Upload a Web Shell to a Web Server.This issue affects Insert or Embed Articulate Content into WordPress: from n/a…
AplazadaAlta (7.1)0.19%—Mathieu Chartier Wp-planificationAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WP-Planification wp-planification allows Stored XSS.This issue affects WP-Planification: from n/a through <= 2.3.1.
AplazadaCrítica (9.3)0.51%—Martin Nguyen Nextcart-woocommerce-migrationAI1/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next-Cart Store to WooCommerce Migration nextcart-woocommerce-migration allows SQL Injection.This issue affects Next-Cart Store to WooCommerce Migration: from n/a through <= 3.9.4.
AnalizadaMedia (6.6)0.74%—Artificial Intelligence Project Artificial Intelligence31/3/202516/7/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
AnalizadaAlta (7.5)0.76%—Artificial Intelligence Project Artificial Intelligence31/3/202516/7/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.
AnalizadaAlta (8.2)0.37%—Artificial Intelligence Project Artificial Intelligence31/3/202517/6/2026
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.
AnalizadaAlta (8.8)0.22%—Artificial Intelligence Project Artificial Intelligence31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.
AplazadaMedia (5.9)0.30%—Ays-pro ChartifyAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify chart-builder allows Stored XSS.This issue affects Chartify: from n/a through <= 3.1.7.
AnalizadaCrítica (9.8)0.60%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.
ModificadaCrítica (9.8)0.59%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.
ModificadaAlta (7.8)0.29%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.
AnalizadaAlta (7.8)0.26%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.
AnalizadaAlta (7.8)0.22%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.
ModificadaCrítica (9.8)0.82%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.
ModificadaCrítica (9.8)0.59%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.
ModificadaAlta (7.8)0.30%—Artifex Ghostscript25/3/202517/6/2026
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.
AnalizadaAlta (8.6)1.2%—Artica Pandora FMS17/3/202517/6/2026
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .
AnalizadaAlta (8.6)61%💥 ExploitArtica Pandora FMS17/3/202517/6/2026
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
AplazadaAlta (7.1)0.15%—Martin WP Compare TablesAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables wp-compare-tables allows Stored XSS.This issue affects WP Compare Tables: from n/a through <= 1.0.5.
AnalizadaAlta (7.8)0.34%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
AnalizadaAlta (7.8)0.50%💥 PoCParagon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.