Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.40% | — | Convertplug ConvertplusAI | 28/9/2026 | 29/9/2026 | The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the… | |
| Aplazada | Alta (8.3) | 0.57% | — | Gettext-converterAI | 14/9/2026 | 30/9/2026 | gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each segment as a dynamic object key without rejecting __proto__,… | |
| Aplazada | Alta (8.6) | 0.63% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 1.9% | — | Contec CAN 2.0b Communication Wireless LAN USB Converter UnitAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.3) | 0.30% | — | Moreconvert Woocommerce WishlistAI | 11/9/2026 | 11/9/2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. | |
| Aplazada | Alta (7.1) | 0.48% | — | C4illin ConvertxAI | 4/9/2026 | 10/9/2026 | ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path} or \\verbatiminput{path} directives to have the TeX engine read arbitrary files… | |
| Aplazada | Media (6.5) | 0.42% | — | Libreoffice-convertAI | 27/8/2026 | 9/9/2026 | libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base name. A filename containing ../ can escape the temporary directory because… | |
| Aplazada | Media (6.9) | 0.45% | — | Tassos Convert FormsAIJoomlaAI | 20/8/2026 | 26/8/2026 | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Brainstormforce Convert PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Alta (8.2) | 0.31% | — | Tassos.gr Convert FormsAI | 23/7/2026 | 23/7/2026 | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | |
| Aplazada | Media (5.4) | 0.23% | — | Jupyter NbconvertAI | 26/6/2026 | 26/6/2026 | A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to… | |
| Pendiente de análisis | Alta (8.7) | 0.28% | — | Draeger CoreAIDraeger M540 Converter ServiceAI | 2/6/2026 | 22/7/2026 | Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Alta (8.6) | 0.14% | — | Allok AVI Divx Mpeg TO DVD ConverterAI | 17/5/2026 | 17/6/2026 | Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH chain overwrite… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Hrconvert2AI | 14/5/2026 | 17/6/2026 | HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its strip list. User input then reaches shell_exec(), where the shell interprets these characters and commands within… | |
| Aplazada | Media (5.3) | 0.33% | — | Moreconvert Woocommerce WishlistAI | 7/5/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0. | |
| Aplazada | Crítica (9.8) | 0.83% | — | Moreconvert PROAI | 5/5/2026 | 17/6/2026 | The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.6) | 0.17% | — | Alloksoft WMV TO AVI Mpeg DVD WMV ConverterAI | 29/4/2026 | 17/6/2026 | Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handler (SEH) overwrite… | |
| Aplazada | Alta (8.5) | 0.16% | — | Allok AVI TO DVD Svcd VCD ConverterAI | 29/4/2026 | 17/6/2026 | Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler… | |
| Analizada | Media (6.5) | 0.46% | — | Jupyter Nbconvert | 21/4/2026 | 17/6/2026 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate… | |
| Analizada | Media (6.5) | 0.40% | — | Jupyter Nbconvert | 21/4/2026 | 17/6/2026 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The… | |
| Aplazada | Baja (2.1) | 0.52% | — | P2r3 ConvertAI | 20/4/2026 | 17/6/2026 | A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the component API. Performing a manipulation of the argument pathname results in path traversal. It is possible to initiate the attack remotely. The exploit is… | |
| Analizada | Alta (8.6) | 0.21% | — | Ether Software Easy Video TO Ipod Converter | 12/4/2026 | 17/6/2026 | Easy Video to iPod Converter 1.6.20 contains a local buffer overflow vulnerability in the user registration field that allows local attackers to overwrite the structured exception handler. Attackers can input a crafted payload exceeding 996 bytes in the username field to trigger SEH overwrite and execute arbitrary… |