Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.57% | — | PgvectorAI | 25/2/2026 | 17/6/2026 | Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server. | |
| Aplazada | Alta (7.5) | 2.6% | 💥 Exploit | Gvectors WpforoAI | 19/2/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.53% | — | Gvectors WpforoAI | 11/2/2026 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP… | |
| Aplazada | Media (6.4) | 0.28% | — | WP Dsgvo ToolsAI | 23/1/2026 | 17/6/2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content_block' shortcode in all versions up to, and including, 3.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.34% | — | Gvectors WpdiscuzAI | 30/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.43. | |
| Aplazada | Alta (7.8) | 0.16% | — | Tradingview DesktopAIElectronAI | 23/12/2025 | 17/6/2026 | TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Alta (7.8) | 0.37% | — | Cogview4AIHuggingface DiffusersAI | 23/12/2025 | 17/6/2026 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.5) | 0.28% | — | Gvectors WpforoAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10. | |
| Aplazada | Alta (7.5) | 0.38% | — | Gvectors WpforoAI | 14/12/2025 | 7/10/2026 | The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parameters in all versions up to, and including, 2.4.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (6.9) | 0.26% | — | Nagvis | 3/12/2025 | 17/6/2026 | User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames. | |
| Aplazada | Media (6.5) | 0.28% | 💥 PoC | Gvectors WpforoAI | 1/11/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.5) | 0.37% | — | Gvectors WpforoAI | 25/10/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT… | |
| Aplazada | Media (4.3) | 0.31% | — | Realmagvii MdtfAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.3.9. | |
| Aplazada | Crítica (10) | 1.3% | — | Geovision Gv-bx1500AIGeovision Gv-mfd1501AI | 20/10/2025 | 17/6/2026 | GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models have been declared end-of-life (EOL) by the vendor. VulnCheck has observed this… | |
| Aplazada | Media (4.3) | 0.20% | — | Gvectors WpdiscuzAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.33. | |
| Aplazada | Media (4.3) | 0.34% | — | Gvectors WpforoAI | 3/9/2025 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.6. | |
| Aplazada | Media (5.4) | 0.23% | — | Gvectors WpforoAI | 10/7/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary… | |
| Aplazada | Alta (8.1) | 0.58% | — | Unfoldwp BlogvyAI | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogvy blogvy allows PHP Local File Inclusion.This issue affects Blogvy: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.2) | 0.24% | — | Wpforo Advanced AttachmentsAIGvectors WpforoAI | 3/6/2025 | 17/6/2026 | The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and… | |
| Modificada | Media (5.1) | 0.22% | — | Nagvis | 27/5/2025 | 17/6/2026 | Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS | |
| Modificada | Media (5.3) | 0.39% | — | Nagvis | 27/5/2025 | 17/6/2026 | Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection | |
| Aplazada | Media (6.5) | 0.22% | — | Eric-oliver Machler Dsgvo YoutubeAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube dsgvo-youtube allows DOM-Based XSS.This issue affects DSGVO Youtube: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.6) | 0.29% | — | Gvectors Wpforo ForumAI | 4/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum wpforo allows Privilege Escalation.This issue affects wpForo Forum: from n/a through <= 2.4.2. | |
| Analizada | Media (6.8) | 0.07% | — | Google Gvisor | 28/3/2025 | 17/6/2026 | Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork. | |
| Analizada | Media (6.5) | 0.38% | — | Gvectors Wpforo Forum | 28/2/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary… |