Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

3426 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.31%💥 PoCCyntler React DOC ViewerAI20/5/202623/7/2026
Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode
AnalizadaBaja (3.7)0.27%—Adcisolutions Node View Permissions19/5/202623/7/2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.
Pendiente de análisisMedia (6.3)0.34%—Teamviewer DEX Platform On-premisesAI13/5/202617/6/2026
A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution…
AnalizadaMedia (5.5)0.59%—Microsoft Live Preview12/5/202617/6/2026
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
AplazadaAlta (8.5)0.36%—Aman Views Views FOR Wpforms LiteAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6.
AplazadaAlta (8.5)0.36%—Aman Views FOR Ninja FormsAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views &#8211; Display &amp; Edit Ninja…
AplazadaMedia (4.3)0.36%—Rate Star Review VoteAI12/5/202617/6/2026
The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() check. When the…
AplazadaAlta (8.7)0.54%—Link Preview JSAI11/5/202617/6/2026
Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1.
AplazadaCrítica (10)0.55%—Remote Spark SparkviewAI8/5/202617/6/2026
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
AplazadaBaja (2.1)1.8%—Crazyrabbitltc Mcp-code-review-serverAI2/5/202617/6/2026
A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiated remotely. The exploit is now public…
AplazadaMedia (6.9)0.12%—WansviewAI26/4/202617/6/2026
Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes.
AplazadaAlta (8.6)0.15%—IsmartviewproAI26/4/202617/6/2026
iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH…
AnalizadaCrítica (10)1.1%—Microsoft Purview Ediscovery23/4/202617/6/2026
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.5)0.15%—Skygroup Skymec IT ManagerSkygroup Skysea Client View20/4/202617/6/2026
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the…
AplazadaMedia (6.1)0.29%—Cusrev Customer Reviews FOR WoocommerceAI16/4/202617/6/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (4.3)0.23%—Bplugins 3D Viewer Embed 3D ModelsAI15/4/202617/6/2026
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
AplazadaMedia (4.4)0.22%—List View Google CalendarAI15/4/202617/6/2026
The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to…
AnalizadaMedia (6.3)0.14%—Siemens Simcenter 3DSiemens Simcenter FemapSiemens Simcenter Star-ccm+ ViewerSiemens Software Center+314/4/202629/6/2026
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0…
AnalizadaBaja (2.7)0.32%—Janobe Online Reviewer System13/4/202617/6/2026
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.
AnalizadaBaja (2.7)0.32%—Janobe Online Reviewer System13/4/202617/6/2026
Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.
AplazadaMedia (5.3)0.57%—Cusrev Customer Reviews FOR WoocommerceAI10/4/202617/6/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict…
AplazadaMedia (5.1)0.19%—Joomla Jlex ReviewAI9/4/202626/9/2026
Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking…
AplazadaMedia (6)0.21%—Bootstrapped Visual Link PreviewAI8/4/202624/7/2026
Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0.
AplazadaMedia (5.3)0.31%—G5theme Book Previewer FOR WoocommerceAI8/4/202624/7/2026
Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through <= 1.0.6.
AplazadaMedia (5.3)0.26%—Wpmet WP Ultimate ReviewAI8/4/202624/7/2026
Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wp Ultimate Review: from n/a through <= 2.3.8.