Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.11%—Intel Graphics DriverAI12/8/202517/6/2026
Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.22%—Paragraphs Table Project Paragraphs Table26/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs table allows Cross-Site Scripting (XSS).This issue affects Paragraphs table: from 2.0.0 before 2.0.5.
AplazadaMedia (5.9)0.25%—Vicchi WP BiographiaAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vicchi WP Biographia wp-biographia allows Stored XSS.This issue affects WP Biographia: from n/a through <= 4.0.0.
AnalizadaAlta (7.5)0.37%—Themegoods Photography6/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.
AplazadaMedia (5.4)0.15%—Intel Graphics SoftwareAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.9)0.17%—Intel Graphics DriversAI13/5/202517/6/2026
Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
AplazadaMedia (6.8)0.16%—Intel Graphics DriversAI13/5/202517/6/2026
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.14%—Intel Graphics SoftwareAI13/5/202517/6/2026
Improper access control for some Intel(R) Graphics software may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.4)0.15%—Intel Graphics SoftwareAIIntel ARC GraphicsAIIntel Iris XE GraphicsAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0.101.6325/32.0.101.6252 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.8)0.16%—Intel Graphics DriversAI13/5/202517/6/2026
Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.15%—Intel Graphics DriversAI13/5/202517/6/2026
Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.3)0.20%—Intel Graphics DriverAI13/5/202517/6/2026
Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.15%—Intel Graphics DriverAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.15%—Intel ARC Iris XE Graphics SoftwareAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.2)0.14%—Intel ARC AND Iris XE Graphics SoftwareAI13/5/202517/6/2026
Improper access control for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.1)0.14%—Intel ARC Iris XE Graphics SoftwareAI13/5/202517/6/2026
Improper access control for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 31.0.101.4032 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (4.8)0.16%—Intel Graphics DriverAI13/5/202517/6/2026
Out-of-bounds read for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable information disclosure via local access.
AplazadaMedia (5.8)0.16%—Intel Graphics DriverAI13/5/202517/6/2026
Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.4)0.13%—Intel Graphics DriverAI13/5/202517/6/2026
Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.1)0.36%💥 PoCIqonic Design GraphinaAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This issue affects Graphina: from n/a through <= 3.0.4.
AplazadaMedia (5.4)0.33%—Iqonic Design GraphinaAI7/5/202517/6/2026
Missing Authorization vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Graphina: from n/a through <= 3.0.4.
AplazadaAlta (7.1)0.29%—Graphems List-urlsAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls list-urls allows Reflected XSS.This issue affects List Urls: from n/a through <= 0.2.
AplazadaMedia (6.5)0.27%—Graphthemes Glossy BlogAI15/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphthemes Glossy Blog glossy-blog allows Stored XSS.This issue affects Glossy Blog: from n/a through <= 1.0.3.
AplazadaMedia (5.4)0.21%—Themegoods PhotographyAI15/4/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photography: from n/a through < 7.7.6.
AplazadaMedia (5.1)0.33%—Demtec GraphyticsAI15/4/202517/6/2026
A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unknown code of the file /visualization. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and…