Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.67% | — | Nasatheme ElessiAI | 4/7/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi elessi-theme allows PHP Local File Inclusion.This issue affects Elessi: from n/a through < 6.4.1. | |
| Aplazada | Crítica (9.3) | 0.64% | — | Sapido Wireless RouterAI | 24/6/2025 | 17/6/2026 | Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials. The affected models are out of support; replacing the device is recommended. | |
| Aplazada | Crítica (9.3) | 1.7% | — | Sapido Wireless RouterAI | 24/6/2025 | 17/6/2026 | Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended. | |
| Aplazada | Alta (7.1) | 0.26% | — | Nasatheme ElessiAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi elessi-theme allows Reflected XSS.This issue affects Elessi: from n/a through <= 6.3.9. | |
| Aplazada | Crítica (9.4) | 0.22% | — | Cyclone Matrix TRF Smart Keyless Entry SystemAIKIA SolutoAI | 13/6/2025 | 17/6/2026 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack confirmed on other KIA Models in Ecuador. | |
| Aplazada | Crítica (9.4) | 0.68% | — | KIA Smart Keyless Entry SystemAI | 13/6/2025 | 17/6/2026 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release. CVE Record will be updated once… | |
| Aplazada | Alta (7.2) | 1.4% | — | Hikvision Wireless Access PointAI | 13/6/2025 | 17/6/2026 | Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | |
| Aplazada | Media (4.3) | 0.16% | — | Alessandro Piconi Simple Keyword TO LinkAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5. | |
| Aplazada | Media (6.4) | 0.30% | — | Visualmodo BorderlessAI | 31/5/2025 | 17/6/2026 | The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (5.7) | 0.16% | — | Hypr PasswordlessAI | 21/5/2025 | 17/6/2026 | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1. | |
| Aplazada | Media (5.9) | 0.12% | — | Hypr PasswordlessAI | 21/5/2025 | 17/6/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | Validas Wireless ButlerAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in validas Wireless Butler wireless-butler allows Reflected XSS.This issue affects Wireless Butler: from n/a through <= 1.0.11. | |
| Analizada | Alta (8.3) | 0.17% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Alta (7) | 0.21% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Alta (7.2) | 0.22% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (6.9) | 0.16% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Alta (8.3) | 0.16% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Alta (7) | 0.21% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Alta (8.3) | 0.25% | — | Intel Proset/wireless Wifi | 13/5/2025 | 17/6/2026 | Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Alessandro Rubini GPMAI | 12/5/2025 | 17/6/2026 | The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system. | |
| Aplazada | Alta (7.4) | 0.25% | — | Cisco IOSAICisco IOS XEAICisco Nx-osAICisco Wireless LAN ControllerAI | 7/5/2025 | 17/6/2026 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Aplazada | Media (4.3) | 0.17% | — | Chris Clark Lessbuttons Social Sharing AND StatisticsAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics lessbuttons allows Cross Site Request Forgery.This issue affects LessButtons Social Sharing and Statistics: from n/a through <= 1.6.1. | |
| Aplazada | Crítica (9.8) | 0.55% | — | OTP Less ONE TAP Sign INAI | 2/5/2025 | 17/6/2026 | The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due to the plugin not properly validating a user's identity prior to updating their details, like email. This makes it possible for unauthenticated attackers to change… | |
| Modificada | Alta (8.8) | 0.95% | — | GFI Mailessentials | 28/4/2025 | 17/6/2026 | GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup. | |
| Modificada | Media (6.5) | 0.72% | — | GFI Mailessentials | 28/4/2025 | 17/6/2026 | GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files. |