Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
512 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.44% | — | Servit Affiliate-toolkitAI | 10/7/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4. | |
| Aplazada | Alta (8.8) | 0.58% | — | Swiss Toolkit FOR WPAI | 29/5/2024 | 17/6/2026 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for authenticated attackers with contributor-level and above permissions to… | |
| Analizada | Alta (7.8) | 0.19% | — | Intel AdvisorIntel Oneapi Base Toolkit | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.7) | 0.26% | — | Merge Dicom ToolkitAI | 3/5/2024 | 17/6/2026 | Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception. | |
| Aplazada | Media (4) | 0.19% | — | Merge Dicom ToolkitAI | 3/5/2024 | 17/6/2026 | Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation. | |
| Aplazada | Media (4) | 0.19% | — | Merge Dicom ToolkitAI | 3/5/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation. | |
| Aplazada | Media (4.3) | 0.46% | — | Ovic Team Ovic Addon ToolkitAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Ovic Team Ovic Addon Toolkit.This issue affects Ovic Addon Toolkit: from n/a through 2.6.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Munir Kamal Gutenberg Block Editor ToolkitAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munir Kamal Gutenberg Block Editor Toolkit allows Stored XSS.This issue affects Gutenberg Block Editor Toolkit: from n/a through 1.40.4. | |
| Analizada | Alta (8.1) | 1.6% | — | Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+6 | 17/4/2024 | 4/8/2026 | A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that… | |
| Analizada | Baja (3.3) | 0.23% | — | Nvidia Cuda Toolkit | 5/4/2024 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service. | |
| Analizada | Baja (3.3) | 0.23% | — | Nvidia Cuda Toolkit | 5/4/2024 | 17/6/2026 | NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service. | |
| Aplazada | Media (5.1) | 0.17% | — | Softing Uatoolkit EmbeddedAI | 2/4/2024 | 17/6/2026 | An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is mishandled, leading to memory consumption. When that happens often enough, the device will be out of memory, i.e., a denial of service. | |
| Modificada | Media (6.1) | 0.96% | 💥 Exploit | Uncannyowl Uncanny Toolkit FOR Learndash | 27/3/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3. | |
| Aplazada | Alta (7.1) | 0.42% | — | Madfishdigital Bulk Noindex AND Nofollow ToolkitAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01. | |
| Aplazada | Media (6.5) | 0.34% | — | Servit Affiliate-toolkitAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit allows Stored XSS.This issue affects affiliate-toolkit: from n/a through 3.4.5. | |
| Modificada | Media (4.3) | 0.32% | — | Servit Affiliate-toolkit | 8/3/2024 | 17/6/2026 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (6.5) | 0.29% | — | Servit Affiliate-toolkit | 8/3/2024 | 17/6/2026 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Crítica (9.8) | 0.64% | — | Prestatoolkit Make AN Offer/offer Your Price | 8/3/2024 | 17/6/2026 | In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` . | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Assistive Context-aware Toolkit | 14/2/2024 | 17/6/2026 | Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6) | 0.17% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.8) | 0.58% | — | Pixee Java Code Security Toolkit | 1/2/2024 | 17/6/2026 | The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable to the bypass, the application must use toolkit version <=1.1.1, use ZipSecurity as a guard against path traversal, and… | |
| Modificada | Alta (7.1) | 0.95% | — | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Z+3 | 26/1/2024 | 22/9/2026 | A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users. | |
| Modificada | Media (5.3) | 0.36% | — | Integrationobjects OPC UA Server Toolkit | 16/1/2024 | 17/6/2026 | OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field. | |
| Modificada | Crítica (9.8) | 0.90% | — | Servit Affiliate-toolkit | 1/1/2024 | 17/6/2026 | The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request… |