Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper ReviewxAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. | |
| Aplazada | Media (6.3) | 0.25% | — | Ljapps WP Google Review SliderAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions. | |
| Aplazada | Media (5.3) | 0.47% | — | Helpfulcrowd Product ReviewsAI | 9/6/2026 | 23/7/2026 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict comparison (`!==`) when validating the… | |
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Markdown Preview EnhancedAICrossnoteAIWavedromAIMicrosoft VS CodeAI | 5/6/2026 | 23/7/2026 | Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the… | |
| Aplazada | Alta (8.6) | 0.64% | — | Markdown Preview EnhancedAIWavedromAI | 5/6/2026 | 17/6/2026 | Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll()/eva() helpers) -… | |
| Aplazada | Alta (8.6) | 0.56% | — | Markdown Preview EnhancedAI | 5/6/2026 | 17/6/2026 | Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled code on the server… | |
| Aplazada | Alta (8.6) | 0.47% | 💥 PoC | Markdown Preview EnhancedAI | 5/6/2026 | 17/6/2026 | Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - the diagram filename attribute, imported file paths, and the latex_engine code-chunk attribute. On Windows, a crafted markdown document can… | |
| Aplazada | Alta (8.8) | 0.26% | — | Google Review SliderAI | 4/6/2026 | 22/7/2026 | WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract… | |
| Aplazada | Alta (7.8) | 0.20% | — | Wassimulator CactusviewerAI | 3/6/2026 | 22/7/2026 | A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL. | |
| Aplazada | Baja (1.9) | 0.12% | — | Sourcecodester Customer Review APPAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service. The attack requires a local approach. The exploit… | |
| Aplazada | Alta (8.5) | 0.14% | — | Fujitsu Serverview AgentsAI | 1/6/2026 | 22/7/2026 | Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege. | |
| Aplazada | Alta (8.5) | 0.14% | — | Fujitsu Serverview Agents FOR WindowsAI | 1/6/2026 | 22/7/2026 | Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege. | |
| Aplazada | Crítica (10) | 0.52% | — | Remotespark SparkviewAI | 29/5/2026 | 21/7/2026 | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated… | |
| Aplazada | Media (5.3) | 0.28% | — | KidsviewAI | 28/5/2026 | 17/6/2026 | A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3 | |
| Aplazada | Crítica (9.8) | 0.65% | — | Goobi ViewerAIApache SolrAI | 27/5/2026 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server… | |
| Analizada | Media (5.5) | 0.29% | — | Jenkins Buildgraph-view | 27/5/2026 | 17/6/2026 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views. | |
| Aplazada | Alta (7.1) | 0.45% | — | Easy ViewAI | 27/5/2026 | 17/6/2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality. | |
| Analizada | Alta (7.5) | 0.37% | — | Viewcomponent View Component | 26/5/2026 | 24/7/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe… | |
| Aplazada | Media (6.5) | 0.37% | — | Viewcomponent View ComponentAI | 26/5/2026 | 24/7/2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls it with public_send. The code does not verify that the requested method is one of the preview examples explicitly… | |
| Aplazada | Media (4.6) | 0.20% | — | Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI | 26/5/2026 | 24/7/2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi… | |
| Aplazada | Alta (7.5) | 0.39% | — | Plainviewplugins MycryptocheckoutAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161. | |
| Aplazada | Alta (8.7) | 0.78% | — | Pcviewer Vt1000AI | 25/5/2026 | 23/7/2026 | PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use path traversal sequences ../../../../../../../../../../../../etc/passwd to access sensitive system files outside the… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Teamviewer DEX PlatformAI | 22/5/2026 | 23/7/2026 | A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles.… | |
| Aplazada | Media (6.1) | 0.37% | — | CBX 5 Star Rating ReviewAI | 22/5/2026 | 23/7/2026 | The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Crítica (9.4) | 0.33% | — | Altium Enterprise Server ViewerAI | 20/5/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a… |