Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.41%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_category. Manipulating the argument id can result in SQL injection.
AnalizadaMedia (5.3)0.24%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection.
AnalizadaMedia (6.3)0.37%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_item. Manipulating the argument id can result in SQL injection.
AnalizadaCrítica (9.8)0.65%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection.
AnalizadaCrítica (9.8)0.65%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_category. Manipulating the argument id can result in SQL injection.
AnalizadaMedia (5.4)0.36%—Dino Physics School Assistant Project Dino Physics School Assistant30/5/202417/6/2026
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts unidentified code within the file /classes/Users.php. Manipulating the argument id results in cross-site scripting.
AnalizadaAlta (7.8)0.54%—Dlink Network Assistant23/5/202417/6/2026
D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of D-Link Network Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in…
ModificadaMedia (6.1)0.33%—Davidlingren Media Library Assistant22/5/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaMedia (6.5)0.53%—Davidlingren Media Library Assistant22/5/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AnalizadaAlta (7.3)0.21%—Intel Driver & Support Assistant16/5/202417/6/2026
Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.25%—Intel Driver & Support Assistant3/5/202417/6/2026
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in…
AnalizadaAlta (7.8)0.33%—Intel Driver & Support Assistant3/5/202417/6/2026
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in…
AplazadaMedia (5.3)0.44%—Fastline Media LLC Assistant Every DAY Productivity AppsAI29/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant – Every Day Productivity Apps.This issue affects Assistant – Every Day Productivity Apps: from n/a through 1.4.9.1.
ModificadaAlta (7.7)0.49%—Davidlingren Media Library Assistant9/4/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AplazadaAlta (8.5)0.52%—Codeisawesome Aikit Wordpress AI Writing Assistant Using Gpt3AI9/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1.
ModificadaMedia (5.4)0.44%—Davidlingren Media Library Assistant29/3/202417/6/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaMedia (6.1)0.23%—Wpassist Countdown Widget27/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPress Countdown Widget: from n/a through 3.1.9.1.
AplazadaAlta (8.7)0.46%—Echo Plugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI27/3/202417/6/2026
Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.30.2.
AnalizadaCrítica (9.8)64%💥 ExploitLG LED Assistant25/3/202417/6/2026
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
AnalizadaCrítica (9.8)51%💥 ExploitLG LED Assistant25/3/202417/6/2026
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
ModificadaMedia (6.5)0.21%—Intel Quickassist Technology Driver14/2/202417/6/2026
Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.17%—Intel Assistive Context-aware Toolkit14/2/202417/6/2026
Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.18%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.