Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Crítica (9.3) | 0.67% | — | Varaneckas JAD Java Decompiler | 28/3/2026 | 17/6/2026 | JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a… | |
| Analizada | Crítica (9.3) | 0.67% | — | Varaneckas JAD Java Decompiler | 28/3/2026 | 17/6/2026 | JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute… | |
| Analizada | Media (5.4) | 0.12% | — | Intel High Level Synthesis Compiler | 12/12/2025 | 17/6/2026 | The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability | |
| Analizada | Media (5.4) | 0.12% | — | Intel High Level Synthesis Compiler | 12/12/2025 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3. | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Oneapi Dpc++ C++ CompilerAIIntel Fpga Support PackageAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation… | |
| Aplazada | Media (4.3) | 0.14% | — | Yonifre Lenix Scss CompilerAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Cross Site Request Forgery.This issue affects Lenix scss compiler: from n/a through <= 1.2. | |
| Aplazada | Media (5.9) | 0.23% | — | Yonifre Lenix Scss CompilerAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Stored XSS.This issue affects Lenix scss compiler: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.14% | — | Bytes.co WP CompilerAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bytes.co WP Compiler wp-compiler allows Cross Site Request Forgery.This issue affects WP Compiler: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Oneapi Dpc++ C++ CompilerAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Oneapi Dpc++/c++ CompilerAI | 12/8/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.25% | — | Wordwebsoftware Crossword Compiler PuzzlesAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Stored XSS.This issue affects Crossword Compiler Puzzles: from n/a through <= 14.5. | |
| Aplazada | Crítica (9.9) | 0.50% | — | Wordwebsoftware Crossword Compiler PuzzlesAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Upload a Web Shell to a Web Server.This issue affects Crossword Compiler Puzzles: from n/a through <= 5.2. | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Oneapi Dpc++/c++ CompilerAI | 13/5/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.5) | 0.56% | — | Apollo RouterAITarget CompilerAI | 9/4/2025 | 17/6/2026 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. This… | |
| Aplazada | Alta (7.5) | 0.42% | — | Apollo CompilerAI | 7/4/2025 | 17/6/2026 | apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. Named fragments were being processed once per fragment spread in some cases during query… | |
| Aplazada | Alta (7.1) | 0.30% | — | THE Jake Group WP Less CompilerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Jake Group WP Less Compiler wp-less-compiler allows Stored XSS.This issue affects WP Less Compiler: from n/a through <= 1.3.0. | |
| Aplazada | Media (5.4) | 0.20% | — | Intel Fpga Support PackageAIIntel Oneapi Dpc++ C++ CompilerAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.20% | — | Intel High Level Synthesis CompilerAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.1) | 0.32% | — | Baonguyenyam WOW Best CSS CompilerAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in baonguyenyam WOW Best CSS Compiler best-css-compiler allows Reflected XSS.This issue affects WOW Best CSS Compiler: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Oneapi Dpc++/c++ CompilerAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI DPC++/C++ Compiler before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Graphics Offline Compiler FOR OpenclAIIntel Graphics DriverAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Graphics Offline Compiler for OpenCL(TM) Code software for Windows before version 2024.1.0.142, graphics driver 31.0.101.5445 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel High Level Synthesis CompilerAIIntel Quartus Prime PRO EditionAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software for Intel(R) Quartus(R) Prime Pro Edition Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.17% | — | Intel Fortran Compiler ClassicAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) Fortran Compiler Classic software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Baja (3.7) | 0.47% | — | ARM Compiler FOR EmbeddedARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Clang | 31/10/2024 | 17/6/2026 | When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an… |