Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.19% | — | Huggingface AccelerateAI | 10/8/2026 | 16/9/2026 | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary… | |
| Aplazada | Media (4.3) | 0.26% | — | Themegrill AccelerateAI | 6/8/2026 | 29/9/2026 | The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the… | |
| Aplazada | Alta (7.8) | 0.37% | — | Huggingface AccelerateAI | 23/12/2025 | 17/6/2026 | Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (6.1) | 0.29% | — | Ampforwp Accelerated Mobile Pages | 18/12/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Alta (8.8) | 0.27% | — | Ampforwp Accelerated Mobile Pages | 25/10/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's… | |
| Modificada | Media (5.4) | 0.33% | — | Ampforwp Accelerated Mobile Pages | 24/7/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and… | |
| Modificada | Media (6.5) | 0.65% | — | Ampforwp Accelerated Mobile Pages | 29/2/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and… | |
| Modificada | Media (6.1) | 0.44% | — | Ampforwp Accelerated Mobile Pages | 23/1/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated… | |
| Modificada | Alta (7.8) | 0.27% | — | Intel Hardware Accelerated Execution Manager | 18/8/2022 | 17/6/2026 | Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.8) | 0.56% | — | Ampforwp Accelerated Mobile Pages | 18/3/2022 | 17/6/2026 | Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32). | |
| Modificada | Media (4.8) | 0.56% | — | Ampforwp Accelerated Mobile Pages | 18/3/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions. | |
| Modificada | Media (6.2) | 0.27% | — | Intel Hardware Accelerated Execution Manager | 17/11/2021 | 17/6/2026 | Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.4) | 0.26% | — | Intel Hardware Accelerated Execution Manager | 17/11/2021 | 17/6/2026 | Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access. | |
| Modificada | Alta (7.8) | 0.37% | — | Intel Hardware Accelerated Execution Manager | 4/4/2017 | 17/6/2026 | Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user to gain system level access. | |
| Modificada | Alta (7.5) | 1.1% | — | Accelerated Enterprise Solutions Accelerated E Solutions | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in an unspecified Accelerated Enterprise Solutions product, possibly Accelerated E Solutions, allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 1.9% | — | Accelerated Enterprise Solutions Accelerated Mortgage Manager | 23/10/2005 | 16/6/2026 | SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field. | |
| Modificada | Alta (7.2) | 0.69% | — | XI Graphics Accelerated-x Server | 25/6/1999 | 16/6/2026 | Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter. |