Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.19%—Huggingface AccelerateAI10/8/202616/9/2026
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary…
AplazadaMedia (4.3)0.26%—Themegrill AccelerateAI6/8/202629/9/2026
The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the…
AplazadaAlta (7.8)0.37%—Huggingface AccelerateAI23/12/202517/6/2026
Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
AnalizadaMedia (6.1)0.29%—Ampforwp Accelerated Mobile Pages18/12/202417/6/2026
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaAlta (8.8)0.27%—Ampforwp Accelerated Mobile Pages25/10/202417/6/2026
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's…
ModificadaMedia (5.4)0.33%—Ampforwp Accelerated Mobile Pages24/7/202417/6/2026
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and…
ModificadaMedia (6.5)0.65%—Ampforwp Accelerated Mobile Pages29/2/202417/6/2026
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and…
ModificadaMedia (6.1)0.44%—Ampforwp Accelerated Mobile Pages23/1/202417/6/2026
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated…
ModificadaAlta (7.8)0.27%—Intel Hardware Accelerated Execution Manager18/8/202217/6/2026
Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.8)0.56%—Ampforwp Accelerated Mobile Pages18/3/202217/6/2026
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
ModificadaMedia (4.8)0.56%—Ampforwp Accelerated Mobile Pages18/3/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
ModificadaMedia (6.2)0.27%—Intel Hardware Accelerated Execution Manager17/11/202117/6/2026
Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access.
ModificadaAlta (8.4)0.26%—Intel Hardware Accelerated Execution Manager17/11/202117/6/2026
Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access.
ModificadaAlta (7.8)0.37%—Intel Hardware Accelerated Execution Manager4/4/201717/6/2026
Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user to gain system level access.
ModificadaAlta (7.5)1.1%—Accelerated Enterprise Solutions Accelerated E Solutions31/12/200516/6/2026
SQL injection vulnerability in an unspecified Accelerated Enterprise Solutions product, possibly Accelerated E Solutions, allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)1.9%—Accelerated Enterprise Solutions Accelerated Mortgage Manager23/10/200516/6/2026
SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.
ModificadaAlta (7.2)0.69%—XI Graphics Accelerated-x Server25/6/199916/6/2026
Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.