Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.33% | — | Wattsense BridgeAI | 11/2/2025 | 17/6/2026 | A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions… | |
| Aplazada | Media (6.1) | 0.29% | — | Wattsense BridgeAI | 11/2/2025 | 17/6/2026 | The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected. | |
| Analizada | Media (5.3) | 0.43% | — | Automattic Sensei LMS | 4/2/2025 | 17/6/2026 | The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information. | |
| Aplazada | Media (6.5) | 0.37% | — | No-nonsense WP Krpano Wp-krpanoAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in No-Nonsense WP krpano wp-krpano allows Stored XSS.This issue affects WP krpano: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Magazine3 Ads-for-wpAIGoogle AdsenseAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Google Adsense & Banner Ads by AdsforWP ads-for-wp allows Cross Site Request Forgery.This issue affects Google Adsense & Banner Ads by AdsforWP: from n/a through <= 1.9.28. | |
| Aplazada | Alta (7.5) | 0.41% | — | Aesensors Ae1021AIAesensors Ae1021peAI | 18/12/2024 | 17/6/2026 | Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string. | |
| Aplazada | Alta (7.5) | 0.35% | — | Qlik Sense EnterpriseAI | 9/12/2024 | 17/6/2026 | An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality risks. This is fixed in November 2024 IR, May 2024 Patch 10,… | |
| Aplazada | Alta (8.8) | 0.47% | — | Qlik Sense EnterpriseAI | 9/12/2024 | 17/6/2026 | An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16,… | |
| Aplazada | Alta (7.8) | 0.15% | — | Cindori Sensei MAC CleanerAI | 25/11/2024 | 17/6/2026 | The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations include arbitrary file deletion and writing, loading and unloading daemons, manipulating file permissions, and loading extensions, among other… | |
| Aplazada | Media (6.5) | 0.24% | — | Dozyde Cookie Nonsense FOR YTAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dozyde Cookie Nonsense for YT yt-cookie-nonsense allows DOM-Based XSS.This issue affects Cookie Nonsense for YT: from n/a through <= 1.2.0. | |
| Analizada | Media (5.1) | 0.39% | — | Timgeyssens Ui-o-matic | 12/11/2024 | 17/6/2026 | A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown code of the file /src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.r. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.8) | 0.43% | — | Sensiolabs Symfony | 6/11/2024 | 17/6/2026 | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has… | |
| Modificada | Media (6.1) | 0.55% | — | Sensiolabs Symfony | 6/11/2024 | 17/6/2026 | symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users… | |
| Analizada | Media (4.3) | 0.47% | — | Sensiolabs Httpclient | 6/11/2024 | 17/6/2026 | symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of… | |
| Analizada | Media (5.5) | 0.33% | — | Consensys Gnark | 31/10/2024 | 17/6/2026 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal error: runtime: out of memory. | |
| Analizada | Media (4.8) | 80% | 💥 PoC | Netgate Pfsense | 22/10/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php. | |
| Analizada | Media (5.9) | 0.43% | — | Consensys Gnark-crypto | 6/9/2024 | 17/6/2026 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16 proofs with commitments. Notably, PLONK proofs are not affected. The… | |
| Analizada | Media (6.2) | 0.19% | — | Consensys Gnark-crypto | 6/9/2024 | 17/6/2026 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commitment. As gnark uses the commitments for optimized non-native multiplication,… | |
| Analizada | Media (5.3) | 1.7% | 💥 Exploit | Automattic Sensei LMS | 4/9/2024 | 17/6/2026 | The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates. | |
| Analizada | Media (5.3) | 0.41% | — | Nissan-global Blind Spot Protection Sensor ECU Firmware | 19/8/2024 | 17/6/2026 | Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests. | |
| Aplazada | Media (5.3) | 0.63% | — | Automattic Sensei LMSAIAutomattic Sensei PROAI | 18/8/2024 | 17/6/2026 | Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1. | |
| Analizada | Media (5.3) | 0.26% | — | Nissan-global Blind Spot Detection Sensor ECU Firmware | 15/8/2024 | 17/6/2026 | — | |
| Modificada | Alta (8.3) | 0.23% | — | Proges Sensor NET Connect Firmware V2 | 31/7/2024 | 17/6/2026 | A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page. | |
| Modificada | Media (4.6) | 0.11% | — | Proges Sensor NET Connect Firmware V2 | 31/7/2024 | 17/6/2026 | A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled. | |
| Analizada | Media (4.6) | 0.19% | — | Proges Sensor NET Connect Firmware V2 | 31/7/2024 | 17/6/2026 | A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser. |