Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Electronic Judging SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Electronic Judging SystemAI | 26/5/2026 | 23/7/2026 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Electronic Judging SystemAI | 24/5/2026 | 23/7/2026 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (6.8) | 0.40% | — | IM Park Information Technology Electronics Press Publishing AND Advertising Education LTD CO DijidemiAI | 14/5/2026 | 17/6/2026 | Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0. | |
| Pendiente de análisis | Media (5.4) | 0.09% | — | Electronhub AI PlaygroundAI | 12/5/2026 | 17/6/2026 | Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially… | |
| Modificada | Alta (8.6) | 0.22% | — | Pengutronix Barebox | 11/5/2026 | 18/7/2026 | barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to… | |
| Modificada | Media (6.9) | 0.18% | — | Pengutronix Barebox | 11/5/2026 | 18/7/2026 | barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry length values are non-zero. Attackers can supply a malicious ext4 filesystem image with a crafted directory… | |
| Modificada | Media (6.9) | 0.22% | — | Pengutronix Barebox | 11/5/2026 | 18/7/2026 | barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.c. Attackers can supply a malicious ext4 filesystem image via USB, SD card, or network boot to trigger heap… | |
| Modificada | Alta (7.1) | 0.38% | — | Pengutronix Barebox | 11/5/2026 | 18/7/2026 | barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within received packet bounds. An attacker on the same broadcast domain can send a crafted DHCP Offer or ACK packet without a… | |
| Pendiente de análisis | Media (6.8) | 0.13% | — | Medtronic Mycarelinkpatient MonitorAI | 7/5/2026 | 17/6/2026 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data. | |
| Pendiente de análisis | Media (6.8) | 0.16% | — | Medtronic Myarelink Patient MonitorAI | 7/5/2026 | 17/6/2026 | Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal. | |
| Aplazada | Media (5.5) | 0.48% | — | Picotronica E-clinic Healthcare System EchsAI | 6/5/2026 | 17/6/2026 | A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ of the component Response Header Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.47% | — | Picotronica E-clinic Healthcare System EchsAI | 6/5/2026 | 17/6/2026 | A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of the argument ADMIN_KEY causes hard-coded credentials. The attack is possible to be carried out remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.68% | — | Picotronica E-clinic Healthcare System EchsAI | 6/5/2026 | 17/6/2026 | A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit is now public… | |
| Pendiente de análisis | Alta (7.4) | 0.98% | — | Crestron DevicesAI | 5/5/2026 | 24/7/2026 | A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A third party researcher Eugene Lim had discovered vulnerability in the way console command passes to a popen function call. Attackers with authenticated access to SSH console of Crestron devices… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Electronic Judging SystemAI | 1/5/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/login.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.9) | 0.24% | — | Zookatron MybooktableAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0. | |
| Aplazada | Media (6.4) | 0.26% | — | Strong TestimonialsAI | 8/4/2026 | 25/7/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Baja (3.3) | 0.14% | — | Electronjs Electron | 7/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode, the resulting… | |
| Analizada | Alta (8.8) | 0.38% | — | Electronjs Electron | 7/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A… | |
| Analizada | Media (5.5) | 0.14% | — | Electronjs Electron | 6/4/2026 | 17/6/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions, the release()… | |
| Modificada | Media (6.1) | 0.45% | — | Electronjs Electron | 4/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are… | |
| Analizada | Alta (7.8) | 0.18% | — | Electronjs Electron | 4/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the application bundle path.… | |
| Analizada | Media (6.5) | 0.14% | — | Electronjs Electron | 4/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and related methods, causing… | |
| Analizada | Media (5.4) | 0.13% | — | Electronjs Electron | 4/4/2026 | 24/7/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was… |