Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Analizada | Alta (7.1) | 0.13% | — | HP Support Assistant | 5/6/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |
| Aplazada | Media (6.2) | 0.08% | — | Transsion AivoiceassistantAI | 15/5/2025 | 17/6/2026 | Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage. | |
| Aplazada | Alta (7.5) | 0.54% | — | Bitapps BIT AssistAI | 1/4/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Bit Apps Bit Assist bit-assist allows Path Traversal.This issue affects Bit Assist: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.9) | 0.23% | — | Davidlingren Media Library AssistantAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.24. | |
| Analizada | Media (6.1) | 0.21% | — | Hliu Large Language AND Vision Assistant | 20/3/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of… | |
| Analizada | Alta (7.5) | 0.86% | — | Hliu Large Language AND Vision Assistant | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server… | |
| Analizada | Alta (7.5) | 0.69% | — | Hliu Large Language AND Vision Assistant | 20/3/2025 | 17/6/2026 | A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path… | |
| Aplazada | Alta (7.2) | 0.70% | — | Beaver Builder Wordpress AssistantAI | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7) | 0.25% | — | AiohttpAIAiohttp SessionAIHome-assistant Home Assistant CoreAI | 18/2/2025 | 17/6/2026 | Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the past, `aiohttp-session`/`request` had the… | |
| Analizada | Media (6.5) | 0.64% | — | Bitapps BIT Assist | 15/2/2025 | 17/6/2026 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Analizada | Media (6.5) | 0.57% | — | Bitapps BIT Assist | 14/2/2025 | 17/6/2026 | Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.9) | 0.66% | — | Bitapps BIT Assist | 14/2/2025 | 17/6/2026 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain… | |
| Analizada | Alta (7.8) | 0.18% | — | Dell Supportassist OS Recovery | 13/2/2025 | 17/6/2026 | Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges. | |
| Analizada | Alta (7.3) | 0.24% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.1) | 0.21% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.4) | 0.20% | — | Intel Quickassist Technology | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.1) | 0.37% | — | Davidlingren Media Library Assistant | 4/1/2025 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.55% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 25/12/2024 | 17/6/2026 | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges… | |
| Analizada | Media (5.9) | 0.35% | — | Watson Assistant FOR IBM Cloud PAK FOR Data | 26/11/2024 | 17/6/2026 | IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash. | |
| Aplazada | Media (6.5) | 0.30% | — | Ezlab Assist24 Help DeskAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ezlab Assist24 Help Desk assist24it allows DOM-Based XSS.This issue affects Assist24 Help Desk: from n/a through <= 20150401.2. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Pushassist Push Notifications FOR WordpressAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssist push-notification-for-wp-by-pushassist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through <= 3.0.8. | |
| Analizada | Media (5.4) | 0.16% | — | Intel Driver & Support Assistant | 13/11/2024 | 17/6/2026 | Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Driver & Support Assistant | 13/11/2024 | 17/6/2026 | Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7) | 0.17% | — | Intel Endpoint Management Assistant | 13/11/2024 | 17/6/2026 | Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |