Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2807▲ 78 respecto a la semana anterior
Críticas / altas1475▲ 316 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.51% | — | Bytes Random Secure TinyAI | 26/6/2026 | 1/7/2026 | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are… | |
| Aplazada | Alta (7.5) | 0.51% | — | Bytes Random SecureAI | 26/6/2026 | 1/7/2026 | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in… | |
| Analizada | Alta (8.5) | 0.22% | — | Malwarebytes | 19/6/2026 | 29/9/2026 | Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during… | |
| Aplazada | Alta (7.5) | 0.22% | — | MalwarebytesAIMalwarebytes NebulaAI | 9/6/2026 | 23/7/2026 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities. | |
| Aplazada | Media (6.2) | 0.12% | — | MalwarebytesAIMalwarebytes NebulaAIMozilla FirefoxAI | 9/6/2026 | 23/7/2026 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service. | |
| Aplazada | Alta (8.2) | 0.12% | — | Malwarebytes EDRAI | 9/6/2026 | 23/7/2026 | The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for… | |
| Aplazada | Alta (8.7) | 0.14% | — | Malwarebytes AdwcleanerAI | 17/2/2026 | 17/6/2026 | Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create… | |
| Analizada | Media (5.5) | 0.60% | — | Tokio-rs Bytes | 4/2/2026 | 17/6/2026 | Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. When new_cap + offset overflows usize in… | |
| Analizada | Baja (3.3) | 0.21% | — | Malwarebytes | 12/12/2025 | 17/6/2026 | Malwarebytes 1.0.14 for Linux doesn't properly compute signatures in some scenarios. This allows a bypass of detection. | |
| Aplazada | Media (5.3) | 0.25% | — | Malwarebytes FOR TeamsAI | 24/10/2025 | 17/6/2026 | In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mbamservice.exe. | |
| Aplazada | Media (4.3) | 0.14% | — | Bytes.co WP CompilerAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bytes.co WP Compiler wp-compiler allows Cross Site Request Forgery.This issue affects WP Compiler: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (9.3) | 0.67% | — | Generalbytes Crypto Application ServerAI | 19/9/2025 | 17/6/2026 | General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation… | |
| Aplazada | Media (6.5) | 0.24% | — | MalwarebytesAIMalwarebytes NebulaAI | 14/8/2025 | 17/6/2026 | An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). There is a Race condition that leads to code execution because of a lack of locks between file verification and execution. | |
| Aplazada | Alta (7.5) | 0.41% | — | MalwarebytesAIMalwarebytes NebulaAI | 14/8/2025 | 17/6/2026 | An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in strings detection utilities lead to system crashes. | |
| Aplazada | Media (6.5) | 0.35% | — | MalwarebytesAIMalwarebytes NebulaAI | 14/8/2025 | 17/6/2026 | An issue was discovered in Malwarebytes 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). A Stack buffer out-of-bounds access exists because of an integer underflow when handling newline characters. | |
| Aplazada | Media (5.2) | 0.12% | — | MalwarebytesAIMalwarebytes NebulaAI | 14/8/2025 | 17/6/2026 | An issue was discovered in Malwarebytes 4.6.14.326 and before and 5.1.5.116 and before (and Nebula 2020-10-21 and later). An Out of bounds read in several disassembling utilities causes stability issues and denial of service. | |
| Aplazada | Media (4.5) | 0.11% | — | Malwarebytes Binisoft Windows Firewall ControlAI | 28/7/2025 | 17/6/2026 | In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation. | |
| Aplazada | Alta (8.2) | 0.41% | — | Bytes Technolab ADD Product Frontend FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Bytes Technolab Add Product Frontend for WooCommerce add-product-frontend-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Product Frontend for WooCommerce: from n/a through <= 1.0.8. | |
| Analizada | Alta (7.8) | 0.29% | — | Malwarebytes Antimalware | 22/11/2024 | 17/6/2026 | Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Malwarebytes Antimalware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit… | |
| Analizada | Media (6.8) | 0.26% | — | Hitbytes Life | 8/11/2024 | 17/6/2026 | An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function. | |
| Aplazada | Media (5.7) | 0.38% | — | Malwarebytes Premium SecurityAI | 1/10/2024 | 17/6/2026 | An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin users. | |
| Modificada | Alta (8.8) | 0.22% | — | Bytesforall Atahualpa | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24. | |
| Modificada | Crítica (9.8) | 1.8% | — | Malwarebytes Binisoft Windows Firewall Control | 4/2/2024 | 17/6/2026 | Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes. | |
| Modificada | Media (5.4) | 0.37% | — | Brontobytes Cookie BAR | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brontobytes Cookie Bar allows Stored XSS.This issue affects Cookie Bar: from n/a through 2.0. | |
| Modificada | Media (5.5) | 0.28% | — | Malwarebytes Endpoint Detection AND ResponseMalwarebytes | 30/6/2023 | 17/6/2026 | In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier. |