Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

437 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AnalizadaCrítica (9.3)0.67%—Varaneckas JAD Java Decompiler28/3/202617/6/2026
JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a…
AnalizadaCrítica (9.3)0.67%—Varaneckas JAD Java Decompiler28/3/202617/6/2026
JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute…
AnalizadaMedia (5.4)0.12%—Intel High Level Synthesis Compiler12/12/202517/6/2026
The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability
AnalizadaMedia (5.4)0.12%—Intel High Level Synthesis Compiler12/12/202517/6/2026
Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hijacking.This issue affects High Level Synthesis Compiler: from 19.1 through 24.3.
AplazadaMedia (5.4)0.11%—Intel Oneapi Dpc++ C++ CompilerAIIntel Fpga Support PackageAI11/11/202517/6/2026
Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation…
AplazadaMedia (4.3)0.14%—Yonifre Lenix Scss CompilerAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Cross Site Request Forgery.This issue affects Lenix scss compiler: from n/a through <= 1.2.
AplazadaMedia (5.9)0.23%—Yonifre Lenix Scss CompilerAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Lenix scss compiler lenix-scss-compiler allows Stored XSS.This issue affects Lenix scss compiler: from n/a through <= 1.2.
AplazadaMedia (4.3)0.14%—Bytes.co WP CompilerAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bytes.co WP Compiler wp-compiler allows Cross Site Request Forgery.This issue affects WP Compiler: from n/a through <= 1.0.0.
AplazadaMedia (5.4)0.13%—Intel Oneapi Dpc++ C++ CompilerAI12/8/202517/6/2026
Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.12%—Intel Oneapi Dpc++/c++ CompilerAI12/8/202517/6/2026
Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.5)0.25%—Wordwebsoftware Crossword Compiler PuzzlesAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Stored XSS.This issue affects Crossword Compiler Puzzles: from n/a through <= 14.5.
AplazadaCrítica (9.9)0.50%—Wordwebsoftware Crossword Compiler PuzzlesAI23/5/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Upload a Web Shell to a Web Server.This issue affects Crossword Compiler Puzzles: from n/a through <= 5.2.
AplazadaMedia (5.4)0.15%—Intel Oneapi Dpc++/c++ CompilerAI13/5/202517/6/2026
Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.5)0.56%—Apollo RouterAITarget CompilerAI9/4/202517/6/2026
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. This…
AplazadaAlta (7.5)0.42%—Apollo CompilerAI7/4/202517/6/2026
apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. Named fragments were being processed once per fragment spread in some cases during query…
AplazadaAlta (7.1)0.30%—THE Jake Group WP Less CompilerAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Jake Group WP Less Compiler wp-less-compiler allows Stored XSS.This issue affects WP Less Compiler: from n/a through <= 1.3.0.
AplazadaMedia (5.4)0.20%—Intel Fpga Support PackageAIIntel Oneapi Dpc++ C++ CompilerAI12/2/202517/6/2026
Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.20%—Intel High Level Synthesis CompilerAI12/2/202517/6/2026
Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.1)0.32%—Baonguyenyam WOW Best CSS CompilerAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in baonguyenyam WOW Best CSS Compiler best-css-compiler allows Reflected XSS.This issue affects WOW Best CSS Compiler: from n/a through <= 2.0.2.
AplazadaMedia (5.4)0.18%—Intel Oneapi Dpc++/c++ CompilerAI13/11/202417/6/2026
Uncontrolled search path in some Intel(R) oneAPI DPC++/C++ Compiler before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.18%—Intel Graphics Offline Compiler FOR OpenclAIIntel Graphics DriverAI13/11/202417/6/2026
Uncontrolled search path in some Intel(R) Graphics Offline Compiler for OpenCL(TM) Code software for Windows before version 2024.1.0.142, graphics driver 31.0.101.5445 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.18%—Intel High Level Synthesis CompilerAIIntel Quartus Prime PRO EditionAI13/11/202417/6/2026
Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software for Intel(R) Quartus(R) Prime Pro Edition Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.17%—Intel Fortran Compiler ClassicAI13/11/202417/6/2026
Uncontrolled search path for some Intel(R) Fortran Compiler Classic software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaBaja (3.7)0.47%—ARM Compiler FOR EmbeddedARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Clang31/10/202417/6/2026
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an…