Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.21%—Adobe DNG Software Development KIT9/12/202517/6/2026
DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaMedia (6.5)0.20%—Dfdevelopment Ronneby Theme CoreAI9/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DFDevelopment Ronneby Theme Core ronneby-core allows DOM-Based XSS.This issue affects Ronneby Theme Core: from n/a through <= 1.5.68.
AplazadaAlta (7.5)0.46%—Dfdevelopment Ronneby Theme CoreAI9/12/20257/10/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DFDevelopment Ronneby Theme Core ronneby-core allows PHP Local File Inclusion.This issue affects Ronneby Theme Core: from n/a through <= 1.5.68.
AplazadaMedia (5.3)0.29%—Levelfourdevelopment WP EasycartAI9/12/20257/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCart: from n/a through <= 5.8.11.
AnalizadaCrítica (10)0.91%—Microsoft Azure Bastion Developer20/11/202517/6/2026
Azure Bastion Elevation of Privilege Vulnerability
AplazadaMedia (5.7)0.15%—Tyco Command Centre ServerAIELM Development Group ELMAI18/11/202517/6/2026
Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to compromise internal device communications. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20…
AnalizadaBaja (2.1)0.31%—1000projects Design & Development OF Student Database Management System17/11/20257/10/2026
A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The manipulation of the argument SubCode results in sql injection. The attack may be performed from remote. The exploit is…
AnalizadaCrítica (9.8)0.42%—Zoom Meeting Software Development KITZoom Workplace13/11/202517/6/2026
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (5.5)0.15%—Zoom Meeting Software Development KITZoom Workplace Desktop13/11/202517/6/2026
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.
AnalizadaCrítica (9.8)0.30%—Zoom Meeting Software Development KITZoom Workplace13/11/20257/10/2026
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.5)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/20257/10/2026
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (6.1)0.19%—Zoom Meeting Software Development KITZoom Workplace Desktop13/11/20257/10/2026
Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.
AnalizadaMedia (6.5)0.10%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure13/11/20257/10/2026
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
AplazadaMedia (6.5)0.15%—Wpdevelop Booking CalendarAI13/11/20257/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Calendar booking allows Stored XSS.This issue affects Booking Calendar: from n/a through <= 10.14.7.
AnalizadaMedia (6.1)0.20%—Centralsquare Community Development12/11/202517/6/2026
Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.
AnalizadaCrítica (9.8)0.45%—Centralsquare Community Development12/11/202517/6/2026
An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials.
AnalizadaCrítica (9.8)0.35%—Centralsquare Community Development12/11/202517/6/2026
A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.
AplazadaAlta (7.5)0.27%—Redhat 3scale Developer PortalAI6/11/202517/6/2026
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.
AplazadaAlta (8.1)0.44%—Blanka Theme Developers Blanka - ONE Page Wordpress ThemeAI6/11/20257/10/2026
Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5.
ModificadaMedia (6.7)0.18%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00432679; Issue ID: MSV-3950.
AnalizadaAlta (8)0.30%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949.
AnalizadaMedia (6.7)0.16%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958.
AnalizadaMedia (4.7)0.10%—Mediatek Software Development KIT4/11/202517/6/2026
In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036.
AnalizadaMedia (6.7)0.16%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435340; Issue ID: MSV-4038.