Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.31% | 💥 PoC | Cyntler React DOC ViewerAI | 20/5/2026 | 23/7/2026 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode | |
| Analizada | Baja (3.7) | 0.27% | — | Adcisolutions Node View Permissions | 19/5/2026 | 23/7/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1. | |
| Pendiente de análisis | Media (6.3) | 0.34% | — | Teamviewer DEX Platform On-premisesAI | 13/5/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution… | |
| Analizada | Media (5.5) | 0.59% | — | Microsoft Live Preview | 12/5/2026 | 17/6/2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Alta (8.5) | 0.36% | — | Aman Views Views FOR Wpforms LiteAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6. | |
| Aplazada | Alta (8.5) | 0.36% | — | Aman Views FOR Ninja FormsAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms Views – Display & Edit Ninja… | |
| Aplazada | Media (4.3) | 0.36% | — | Rate Star Review VoteAI | 12/5/2026 | 17/6/2026 | The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() check. When the… | |
| Aplazada | Alta (8.7) | 0.54% | — | Link Preview JSAI | 11/5/2026 | 17/6/2026 | Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1. | |
| Aplazada | Crítica (10) | 0.55% | — | Remote Spark SparkviewAI | 8/5/2026 | 17/6/2026 | A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker. | |
| Aplazada | Baja (2.1) | 1.8% | — | Crazyrabbitltc Mcp-code-review-serverAI | 2/5/2026 | 17/6/2026 | A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiated remotely. The exploit is now public… | |
| Aplazada | Media (6.9) | 0.12% | — | WansviewAI | 26/4/2026 | 17/6/2026 | Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes. | |
| Aplazada | Alta (8.6) | 0.15% | — | IsmartviewproAI | 26/4/2026 | 17/6/2026 | iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH… | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Purview Ediscovery | 23/4/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.5) | 0.15% | — | Skygroup Skymec IT ManagerSkygroup Skysea Client View | 20/4/2026 | 17/6/2026 | SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the… | |
| Aplazada | Media (6.1) | 0.29% | — | Cusrev Customer Reviews FOR WoocommerceAI | 16/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (4.3) | 0.23% | — | Bplugins 3D Viewer Embed 3D ModelsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5. | |
| Aplazada | Media (4.4) | 0.22% | — | List View Google CalendarAI | 15/4/2026 | 17/6/2026 | The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event description in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Analizada | Media (6.3) | 0.14% | — | Siemens Simcenter 3DSiemens Simcenter FemapSiemens Simcenter Star-ccm+ ViewerSiemens Software Center+3 | 14/4/2026 | 29/6/2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0… | |
| Analizada | Baja (2.7) | 0.32% | — | Janobe Online Reviewer System | 13/4/2026 | 17/6/2026 | Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Janobe Online Reviewer System | 13/4/2026 | 17/6/2026 | Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php. | |
| Aplazada | Media (5.3) | 0.57% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict… | |
| Aplazada | Media (5.1) | 0.19% | — | Joomla Jlex ReviewAI | 9/4/2026 | 26/9/2026 | Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking… | |
| Aplazada | Media (6) | 0.21% | — | Bootstrapped Visual Link PreviewAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0. | |
| Aplazada | Media (5.3) | 0.31% | — | G5theme Book Previewer FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through <= 1.0.6. | |
| Aplazada | Media (5.3) | 0.26% | — | Wpmet WP Ultimate ReviewAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wp Ultimate Review: from n/a through <= 2.3.8. |