Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.45%—Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+133/7/202517/6/2026
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization…
AnalizadaAlta (7.1)0.13%—HP Support Assistant5/6/202517/6/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
AplazadaMedia (6.2)0.08%—Transsion AivoiceassistantAI15/5/202517/6/2026
Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.
AplazadaAlta (7.5)0.54%—Bitapps BIT AssistAI1/4/202517/6/2026
Path Traversal: '.../...//' vulnerability in Bit Apps Bit Assist bit-assist allows Path Traversal.This issue affects Bit Assist: from n/a through <= 1.5.4.
AplazadaMedia (5.9)0.23%—Davidlingren Media Library AssistantAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.24.
AnalizadaMedia (6.1)0.21%—Hliu Large Language AND Vision Assistant20/3/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of…
AnalizadaAlta (7.5)0.86%—Hliu Large Language AND Vision Assistant20/3/202517/6/2026
A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server…
AnalizadaAlta (7.5)0.69%—Hliu Large Language AND Vision Assistant20/3/202517/6/2026
A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path…
AplazadaAlta (7.2)0.70%—Beaver Builder Wordpress AssistantAI3/3/202517/6/2026
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
AplazadaAlta (7)0.25%—AiohttpAIAiohttp SessionAIHome-assistant Home Assistant CoreAI18/2/202517/6/2026
Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the past, `aiohttp-session`/`request` had the…
AnalizadaMedia (6.5)0.64%—Bitapps BIT Assist15/2/202517/6/2026
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive…
AnalizadaMedia (6.5)0.57%—Bitapps BIT Assist14/2/202517/6/2026
Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with…
AnalizadaMedia (4.9)0.66%—Bitapps BIT Assist14/2/202517/6/2026
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain…
AnalizadaAlta (7.8)0.18%—Dell Supportassist OS Recovery13/2/202517/6/2026
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.
AnalizadaAlta (7.3)0.24%—Intel Quickassist Technology12/2/202517/6/2026
Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.1)0.21%—Intel Quickassist Technology12/2/202517/6/2026
Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaMedia (5.4)0.20%—Intel Quickassist Technology12/2/202517/6/2026
Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.1)0.37%—Davidlingren Media Library Assistant4/1/202517/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaAlta (8.8)0.55%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS25/12/202417/6/2026
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges…
AnalizadaMedia (5.9)0.35%—Watson Assistant FOR IBM Cloud PAK FOR Data26/11/202417/6/2026
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.
AplazadaMedia (6.5)0.30%—Ezlab Assist24 Help DeskAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ezlab Assist24 Help Desk assist24it allows DOM-Based XSS.This issue affects Assist24 Help Desk: from n/a through <= 20150401.2.
AplazadaCrítica (9.9)0.49%—Pushassist Push Notifications FOR WordpressAI16/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssist push-notification-for-wp-by-pushassist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through <= 3.0.8.
AnalizadaMedia (5.4)0.16%—Intel Driver & Support Assistant13/11/202417/6/2026
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Driver & Support Assistant13/11/202417/6/2026
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7)0.17%—Intel Endpoint Management Assistant13/11/202417/6/2026
Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.