Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.25% | — | Wpdeveloper Essential Addons FOR ElementorAI | 14/2/2026 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Media (5.5) | 0.16% | — | Adobe DNG Software Development KIT | 10/2/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Media (5.5) | 0.15% | — | Adobe DNG Software Development KIT | 10/2/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a… | |
| Analizada | Alta (7.8) | 0.19% | — | Adobe DNG Software Development KIT | 10/2/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.17% | — | Adobe DNG Software Development KIT | 10/2/2026 | 28/8/2026 | DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (6.9) | 11% | — | Greatdevelopers Certificate | 8/2/2026 | 17/6/2026 | A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument photo results in os command injection. The attack can be executed remotely. This… | |
| Analizada | Media (5.3) | 0.25% | — | Greatdevelopers Certificate | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. This product follows… | |
| Analizada | Media (5.3) | 0.24% | — | Silabs Simplicity Software Development KIT | 5/2/2026 | 20/8/2026 | A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service. | |
| Modificada | Media (6.5) | 0.79% | — | Mediatek Nbiot SDKMediatek Software Development KITOpenwrt | 2/2/2026 | 17/6/2026 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461663 / WCNCR00463309; Issue ID:… | |
| Analizada | Alta (8.8) | 0.30% | — | Mediatek Software Development KITOpenwrt | 2/2/2026 | 17/6/2026 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461651; Issue ID: MSV-4758. | |
| Aplazada | Media (4.4) | 0.31% | — | Cookie Consent FOR DevelopersAI | 24/1/2026 | 17/6/2026 | The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple settings fields in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Katana Network Development Starter KITAI | 23/1/2026 | 17/6/2026 | Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Katana Network Development Starter Kit. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Media (4.3) | 0.30% | — | Wpdeveloper NotificationxAI | 20/1/2026 | 17/6/2026 | The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.2) | 0.28% | — | Wpdeveloper NotificationxAI | 20/1/2026 | 17/6/2026 | The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to… | |
| Aplazada | Media (5.3) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 16/1/2026 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft,… | |
| Analizada | Alta (7) | 0.38% | — | Microsoft Windows Software Development KIT | 13/1/2026 | 17/6/2026 | Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.5) | 0.36% | — | Wpdeveloper BetterdocsAI | 9/1/2026 | 17/6/2026 | The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in… | |
| Analizada | Media (6.5) | 0.15% | — | Wpdeveloper Essential Addons FOR Elementor | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.3. | |
| Modificada | Alta (7.5) | 0.56% | — | NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB | 18/12/2025 | 7/10/2026 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdeveloper Essential Addons FOR ElementorAI | 17/12/2025 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's custom… | |
| Aplazada | Media (4.3) | 0.32% | — | Wpdeveloper Essential BlocksAI | 17/12/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to,… | |
| Analizada | Media (6.5) | 0.57% | — | Uniteddevelopers Document Reader\ | 10/12/2025 | 17/6/2026 | A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal. | |
| Analizada | Media (5.5) | 0.17% | — | Adobe DNG Software Development KIT | 9/12/2025 | 17/6/2026 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this issue to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must… | |
| Analizada | Alta (7.1) | 0.18% | — | Adobe DNG Software Development KIT | 9/12/2025 | 17/6/2026 | DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a… | |
| Analizada | Alta (7.1) | 0.20% | — | Adobe DNG Software Development KIT | 9/12/2025 | 17/6/2026 | DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a… |