Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.13% | — | Intel Data Center GPU Flex Series Windows DriverAI | 13/5/2025 | 17/6/2026 | Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Alta (8.2) | 0.17% | — | Intel Data Center GPU Flex Series Windows DriverAI | 13/5/2025 | 17/6/2026 | Improper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (6.5) | 0.26% | — | Mekshq Meks Flexible ShortcodesAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Flexible Shortcodes meks-flexible-shortcodes allows Stored XSS.This issue affects Meks Flexible Shortcodes: from n/a through <= 1.3.6. | |
| Aplazada | Alta (8.1) | 1.0% | — | Odude Flexi Guest SubmitAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in odude Flexi – Guest Submit flexi allows PHP Local File Inclusion.This issue affects Flexi – Guest Submit: from n/a through <= 4.28. | |
| Aplazada | Alta (7.1) | 0.21% | — | Sodena Frescochat Live ChatAISodena Flexytalk-widgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sodena FrescoChat Live Chat flexytalk-widget allows Stored XSS.This issue affects FrescoChat Live Chat: from n/a through <= 3.2.6. | |
| Aplazada | Media (6.5) | 0.36% | — | Sfaerber Dr-flexAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sfaerber Dr. Flex dr-flex allows Stored XSS.This issue affects Dr. Flex: from n/a through <= 2.0.0. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpdesk Flexible CookiesAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible Cookies flexible-cookies allows Cross Site Request Forgery.This issue affects Flexible Cookies: from n/a through <= 1.1.8. | |
| Aplazada | Alta (7.6) | 0.63% | — | Wppool FlexstockAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPPOOL FlexStock stock-sync-with-google-sheet-for-woocommerce allows Blind SQL Injection.This issue affects FlexStock: from n/a through <= 3.13.1. | |
| Analizada | Alta (8.8) | 34% | — | NI Flexlogger | 18/3/2025 | 17/6/2026 | NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Aplazada | Media (6.4) | 0.31% | — | Flexmls IDX PluginAI | 7/3/2025 | 17/6/2026 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.34% | — | Flexmag Flex MAGAI | 7/3/2025 | 17/6/2026 | The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.5.2. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.28% | — | Flexostudio Flexo SliderAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Flexmls IDXAI | 25/2/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX flexmls-idx allows Object Injection.This issue affects Flexmls® IDX: from n/a through <= 3.14.27. | |
| Aplazada | Media (5.7) | 0.24% | — | Mosaic5g FlexricAI | 25/2/2025 | 17/6/2026 | An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component. | |
| Aplazada | Alta (7.2) | 0.51% | — | Revenueflex Auto AD Inserter Increase Google Adsense AND AD Manager RevenueAI | 24/2/2025 | 17/6/2026 | Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5. | |
| Analizada | Media (4.3) | 0.17% | — | Wpdesk Flexible Wishlist FOR Woocommerce | 18/2/2025 | 17/6/2026 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.28% | — | MAX Chirkov Flexidx Home SearchAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Chirkov FlexIDX Home Search flexidx-home-search allows Stored XSS.This issue affects FlexIDX Home Search: from n/a through <= 2.1.2. | |
| Modificada | Alta (8.8) | 0.51% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanapp module. The issue results from the lack of proper validation of… | |
| Modificada | Alta (8.8) | 0.49% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboardee module. The issue results from improper access control. An… | |
| Analizada | Alta (8.8) | 0.49% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper… | |
| Analizada | Media (6.5) | 0.23% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack… | |
| Analizada | Alta (8.8) | 0.47% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue results from the lack of proper… | |
| Analizada | Alta (8.8) | 0.47% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue results from the lack of… | |
| Aplazada | Alta (8.5) | 0.81% | — | Flexnet PublisherAIOpensslAI | 30/1/2025 | 17/6/2026 | A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file… | |
| Aplazada | Media (6.9) | 2.5% | 💥 Exploit | FlexonAI | 29/1/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4. |