Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.21% | — | Adobe DNG Software Development KIT | 9/12/2025 | 17/6/2026 | DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.5) | 0.20% | — | Dfdevelopment Ronneby Theme CoreAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DFDevelopment Ronneby Theme Core ronneby-core allows DOM-Based XSS.This issue affects Ronneby Theme Core: from n/a through <= 1.5.68. | |
| Aplazada | Alta (7.5) | 0.46% | — | Dfdevelopment Ronneby Theme CoreAI | 9/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DFDevelopment Ronneby Theme Core ronneby-core allows PHP Local File Inclusion.This issue affects Ronneby Theme Core: from n/a through <= 1.5.68. | |
| Aplazada | Media (5.3) | 0.29% | — | Levelfourdevelopment WP EasycartAI | 9/12/2025 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCart: from n/a through <= 5.8.11. | |
| Analizada | Crítica (10) | 0.91% | — | Microsoft Azure Bastion Developer | 20/11/2025 | 17/6/2026 | Azure Bastion Elevation of Privilege Vulnerability | |
| Aplazada | Media (5.7) | 0.15% | — | Tyco Command Centre ServerAIELM Development Group ELMAI | 18/11/2025 | 17/6/2026 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to compromise internal device communications. This issue affects Command Centre Server: 9.30 prior to vCR9.30.251028a (distributed in 9.30.2881 (MR3)), 9.20… | |
| Analizada | Baja (2.1) | 0.31% | — | 1000projects Design & Development OF Student Database Management System | 17/11/2025 | 7/10/2026 | A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The manipulation of the argument SubCode results in sql injection. The attack may be performed from remote. The exploit is… | |
| Analizada | Crítica (9.8) | 0.42% | — | Zoom Meeting Software Development KITZoom Workplace | 13/11/2025 | 17/6/2026 | Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (7.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (5.5) | 0.15% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 17/6/2026 | External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access. | |
| Analizada | Crítica (9.8) | 0.30% | — | Zoom Meeting Software Development KITZoom Workplace | 13/11/2025 | 7/10/2026 | Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 7/10/2026 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.1) | 0.19% | — | Zoom Meeting Software Development KITZoom Workplace Desktop | 13/11/2025 | 7/10/2026 | Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access. | |
| Analizada | Media (6.5) | 0.10% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 7/10/2026 | Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access. | |
| Aplazada | Media (6.5) | 0.15% | — | Wpdevelop Booking CalendarAI | 13/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Calendar booking allows Stored XSS.This issue affects Booking Calendar: from n/a through <= 10.14.7. | |
| Analizada | Media (6.1) | 0.20% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields. | |
| Analizada | Crítica (9.8) | 0.45% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials. | |
| Analizada | Crítica (9.8) | 0.35% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field. | |
| Aplazada | Alta (7.5) | 0.27% | — | Redhat 3scale Developer PortalAI | 6/11/2025 | 17/6/2026 | A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information. | |
| Aplazada | Alta (8.1) | 0.44% | — | Blanka Theme Developers Blanka - ONE Page Wordpress ThemeAI | 6/11/2025 | 7/10/2026 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5. | |
| Modificada | Media (6.7) | 0.18% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00432679; Issue ID: MSV-3950. | |
| Analizada | Alta (8) | 0.30% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949. | |
| Analizada | Media (6.7) | 0.16% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958. | |
| Analizada | Media (4.7) | 0.10% | — | Mediatek Software Development KIT | 4/11/2025 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036. | |
| Analizada | Media (6.7) | 0.16% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435340; Issue ID: MSV-4038. |