Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.21%—Grafana Labs GrafanaAIGrafana Labs Grafana Cloud Migration AssistantAI13/11/202417/6/2026
A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate…
AplazadaMedia (4)0.19%—Callassistant AI Call Assistant ScreenerAI7/11/202417/6/2026
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.
ModificadaAlta (7.2)1.1%—Davidlingren Media Library Assistant4/11/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.
AplazadaMedia (4.3)0.28%—Sovrn Editorial AssistantAI26/10/202417/6/2026
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.1)0.56%—Fusion Chat Chat AI Assistant ASK ME AnythingAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Chatgpt AI AssistantAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaMedia (5.2)0.14%—Jamf PROAIJamf Remote AssistAI22/10/202417/6/2026
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.
AplazadaCrítica (9.8)0.50%—Transsion AivoiceassistantAI16/10/202417/6/2026
Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.
AnalizadaMedia (5.5)0.14%—Samsung Sound Assistant8/10/202417/6/2026
Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.
AnalizadaAlta (7.5)0.85%💥 ExploitAys-pro Chatgpt Assistant27/9/202417/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and…
ModificadaAlta (7.5)0.30%—Ays-pro Chatgpt Assistant27/9/202417/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
AplazadaMedia (4)0.31%—10web AI AssistantAI26/9/202417/6/2026
Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or…
AplazadaAlta (8.8)0.57%—Gladys AssistantAI21/9/202417/6/2026
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
AnalizadaAlta (7.3)0.63%—Ifeelweb Affiliate Super Assistent10/9/202417/6/2026
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled. This makes it possible for…
AnalizadaMedia (4.3)0.34%—Samsung Assistant4/9/202417/6/2026
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.
AnalizadaAlta (7.3)0.32%—Dell Supportassist FOR Home PCS21/8/202417/6/2026
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges.
AnalizadaAlta (8.8)1.3%—Davidlingren Media Library Assistant13/8/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to…
ModificadaMedia (6.1)0.36%—Davidlingren Media Library Assistant2/7/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)0.58%—Davidlingren Media Library Assistant20/6/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
ModificadaCrítica (9.8)0.43%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.
AnalizadaCrítica (9.8)0.56%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization.
AnalizadaMedia (6.1)0.32%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename results in cross-site scripting.
AnalizadaMedia (5.4)0.26%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name results in cross-site scripting.
AnalizadaCrítica (9.8)0.53%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument id can result in SQL injection.
ModificadaCrítica (9.8)0.54%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.
Orbitaley — Vulnerabilidades