Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
9664 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.17% | — | Etlsystems D0116s1ula-22454 FirmwareEtlsystems D0116s1uia-22474 FirmwareEtlsystems C0401s1ula-22418 FirmwareEtlsystems C0801s1ula-22420 Firmware+23 | 26/12/2025 | 17/6/2026 | The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints. | |
| Aplazada | Media (5.3) | 0.33% | — | Opinionstage Poll Survey AND Quiz MakerAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Addonify Quick ViewAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.3) | 0.23% | — | Brave-popup-builderAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3. | |
| Aplazada | Media (6.5) | 0.16% | — | Live Composer Page BuilderAI | 24/12/2025 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22. | |
| Aplazada | Media (4.3) | 0.22% | — | Kibokolabs Watu QuizAI | 24/12/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en Bob Watu Quiz watu permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Watu Quiz: desde n/a hasta menor o igual que 3.4.5. | |
| Aplazada | Media (5.4) | 0.20% | — | Yithemes Yith Slider FOR Page BuildersAI | 24/12/2025 | 7/10/2026 | Vulnerabilidad de Autorización Faltante en YITHEMES YITH Slider for page builders yith-slider-for-page-builders permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a YITH Slider for page builders: desde n/a hasta menor o igual que 1.0.11. | |
| Aplazada | Media (5.3) | 0.25% | — | Claspo Popup BuildersAI | 24/12/2025 | 7/10/2026 | Vulnerabilidad por falta de autorización en integrationclaspo Popup Builder: pop-up de intención de salida, Gira la Rueda, suscripción a boletines, captura de correo electrónico y creador de formularios de generación de leads claspo permite la explotación de niveles de seguridad de control de acceso configurados… | |
| Modificada | Media (6.5) | 0.17% | — | Hasthemes WC Builder | 24/12/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en HasThemes WC Builder wc-builder permite XSS Almacenado. Este problema afecta a WC Builder: desde n/a hasta menor o igual que 1.2.0. | |
| Aplazada | Crítica (9.9) | 0.59% | — | ConduitAIContinuwuityAIGrapevineAITuwunelAI | 23/12/2025 | 17/6/2026 | Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated attacker to force the target server to cryptographically sign arbitrary membership events. Affected products include Conduit prior to version 0.10.10, continuwuity prior to… | |
| Analizada | Alta (7) | 0.21% | — | Fluidsynth | 23/12/2025 | 17/6/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending to unload a DLS file, leading to use of freed memory, if the… | |
| Aplazada | Alta (8.1) | 0.37% | — | Fastlinemedia Beaver BuilderAI | 23/12/2025 | 17/6/2026 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'duplicate_wpml_layout' function in all versions up to, and including, 2.9.4.1. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.32% | — | Learningcircuit Local Deep Research | 23/12/2025 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to… | |
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 22/12/2025 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request… | |
| Aplazada | Media (4.4) | 0.23% | — | Hasthemes WC BuilderAI | 21/12/2025 | 17/6/2026 | The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'heading_color' parameter (and multiple other styling parameters) of the `wpbforwpbakery_product_additional_information` shortcode in all versions up to, and including, 1.2.0 due to… | |
| Aplazada | Media (6.4) | 0.23% | — | Hasthemes WishsuiteAI | 21/12/2025 | 17/6/2026 | The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the 'wishsuite_button' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.7) | 0.33% | — | Esri Arcgis WEB AppbuilderAI | 19/12/2025 | 17/6/2026 | There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the… | |
| Aplazada | Media (6.4) | 0.29% | — | Extendthemes Colibri Page BuilderAI | 19/12/2025 | 17/6/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.2) | 0.57% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric MC Works64AI | 19/12/2025 | 7/10/2026 | Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('OS Command Injection') en la función de teclado de software (en adelante, denominada 'función de teclado numérico') de Mitsubishi Electric GENESIS64 versiones 10.97.2 CFR3 y anteriores, Mitsubishi… | |
| Analizada | Media (4.8) | 0.13% | — | Arduino IDE | 18/12/2025 | 17/6/2026 | Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the application, the malicious… | |
| Analizada | Media (4.8) | 0.13% | — | Arduino IDE | 18/12/2025 | 17/6/2026 | Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the application process,… | |
| Aplazada | Alta (8.8) | 0.43% | — | Add-ons.org PDF Invoice Builder FOR WoocommerceAI | 18/12/2025 | 5/10/2026 | Vulnerabilidad de deserialización de datos no confiables en add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce permite la inyección de objetos. Este problema afecta a PDF Invoice Builder for WooCommerce: desde n/a hasta menor o igual a 6.3.2. | |
| Aplazada | Alta (8.6) | 1.4% | — | Ruijienetworks RG Ap180AI | 18/12/2025 | 7/10/2026 | RG - AP180, la serie AP180 de Puntos de Acceso Inalámbricos de Placa de Pared Interior proporcionada por Ruijie Networks Co., Ltd. contiene una vulnerabilidad de inyección de comandos del sistema operativo. Un comando arbitrario del sistema operativo puede ser ejecutado en el producto por un atacante que inicia sesión… | |
| Aplazada | Media (5.4) | 0.12% | — | Meks Quick Plugin DisablerAI | 16/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This issue affects Meks Quick Plugin Disabler: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.37% | — | Liquidthemes HUB CoreAI | 16/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core allows PHP Local File Inclusion. This issue affects Hub Core: from n/a before 6.0.2. |