Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.16% | — | Sensopart Visor Vision Sensors Firmware | 23/6/2025 | 17/6/2026 | An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges. | |
| Aplazada | Media (6.5) | 0.25% | — | Codemanas Search With TypesenseAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeManas Search with Typesense search-with-typesense allows Stored XSS.This issue affects Search with Typesense: from n/a through <= 2.0.10. | |
| Modificada | Media (4.3) | 0.29% | — | Krasenslavov Featured Image Plus | 30/5/2025 | 17/6/2026 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fip_save_attach_featured function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 0.88% | — | Canon Satera Mf656cdw FirmwareCanon Satera Mf654cdw FirmwareCanon Satera Mf551dw FirmwareCanon Satera Mf457dw Firmware+33 | 26/5/2025 | 17/6/2026 | Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw… | |
| Modificada | Media (4.3) | 0.38% | — | Automattic Sensei LMS | 15/5/2025 | 17/6/2026 | The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page | |
| Modificada | Media (5.4) | 1.3% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 5/7/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and… | |
| Analizada | Alta (8.8) | 12% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN… | |
| Analizada | Media (5.4) | 8.5% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Realsense SDKAI | 13/5/2025 | 17/6/2026 | Incorrect Default Permissions for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Realsense SDKAI | 13/5/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.2) | 0.19% | — | Sprd Ssense ServiceAI | 6/5/2025 | 17/6/2026 | In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | |
| Aplazada | Crítica (9.1) | 0.85% | 💥 PoC | Ksix Zigbee Gateway ModuleAIKsix Door SensorAIKsix Motion SensorAI | 15/4/2025 | 17/6/2026 | A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless… | |
| Aplazada | Media (5.3) | 0.48% | — | Rtakao Sandwich AdsenseAI | 9/4/2025 | 17/6/2026 | Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sandwich Adsense: from n/a through <= 4.0.2. | |
| Aplazada | Media (5.3) | 0.30% | — | Automattic Sensei LMSAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Automattic Sensei LMS sensei-lms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sensei LMS: from n/a through <= 4.24.4. | |
| Aplazada | Alta (7.1) | 0.18% | — | Hotvanrod Adsense Privacy PolicyAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored XSS.This issue affects AdSense Privacy Policy: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.3) | 0.49% | — | Nask BotsenseAI | 17/3/2025 | 17/6/2026 | Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the "extraData" field.This issue affects BotSense in… | |
| Aplazada | Baja (2.5) | 0.16% | — | Carbonblack Cloud Windows SensorAI | 5/3/2025 | 17/6/2026 | Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due to a vulnerability in software. | |
| Aplazada | Alta (7.1) | 0.37% | — | Mohsenshahbazi WP FixtagAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mohsenshahbazi WP FixTag wp-fixtag allows Reflected XSS.This issue affects WP FixTag: from n/a through <= v2.0.2. | |
| Modificada | Media (4.9) | 0.56% | — | Codemanas Search With Typesense | 25/2/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in CodeManas Search with Typesense search-with-typesense allows Path Traversal.This issue affects Search with Typesense: from n/a through <= 2.0.8. | |
| Aplazada | Alta (7.2) | 0.51% | — | Revenueflex Auto AD Inserter Increase Google Adsense AND AD Manager RevenueAI | 24/2/2025 | 17/6/2026 | Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5. | |
| Analizada | Media (4.8) | 0.34% | — | Tommietott Sensly Online Presence | 14/2/2025 | 17/6/2026 | The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.4) | 0.19% | — | Intel Realsense D400 Series UWP DriverAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.1) | 0.26% | — | Crowdstrike Falcon Sensor FOR LinuxAICrowdstrike Falcon Kubernetes Admission ControllerAICrowdstrike Falcon Container SensorAI | 12/2/2025 | 17/6/2026 | CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection… | |
| Aplazada | Alta (8.8) | 0.70% | — | Wattsense BridgeAI | 11/2/2025 | 17/6/2026 | An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct… | |
| Aplazada | Crítica (9.8) | 0.72% | — | Wattsense BridgeAI | 11/2/2025 | 17/6/2026 | The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has… |