Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)1.2%—Jhen0409 React-native-debuggerAI24/9/202625/9/2026
A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack…
AplazadaMedia (4.3)0.54%—DebugkitAICakephpAI26/8/20269/9/2026
DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without…
AplazadaMedia (6.8)0.28%—Code27 Companion HUBAIGoogle Android Debug BridgeAI8/7/202610/7/2026
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components
AplazadaAlta (7.1)0.25%—Wordpress Plugins WP DebuggingAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
AplazadaMedia (5.3)0.44%—Bowo Debug LOG ManagerAI6/6/202623/7/2026
The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, 2.5.0. This is due to the `log_js_errors()` AJAX handler being registered for unauthenticated users via `wp_ajax_nopriv_log_js_errors` and…
AplazadaBaja (2.1)0.52%—Debugmcp Mcp-debuggerAI25/5/202623/7/2026
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted…
AplazadaAlta (8.8)0.61%—Debugger TroubleshooterAI30/3/202617/6/2026
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_troubleshoot_simulate_user cookie value directly as a user ID without any cryptographic validation or authorization checks.…
AplazadaCrítica (9.1)0.51%—Slajerek RetrodebuggerAI24/3/202617/6/2026
Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.
AplazadaAlta (8.5)0.13%—Httpdebugger PROAI15/1/202617/6/2026
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and gain elevated access to the system.
AnalizadaAlta (7.5)0.73%—Symphorien Nixseparatedebuginfod30/12/202517/6/2026
nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.
AplazadaBaja (2.2)0.11%—Google Android Debug BridgeAI24/12/202517/6/2026
ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.
AplazadaMedia (5.4)0.20%—Oleksandr Lysyi Debug LOG ViewerAI9/12/202517/6/2026
Missing Authorization vulnerability in Oleksandr Lysyi Debug Log Viewer debug-log-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Log Viewer: from n/a through <= 2.0.3.
AplazadaMedia (5.3)0.29%—SSP DebugAI5/12/202525/9/2026
The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the plugin storing PHP error logs in a predictable, web-accessible location (wp-content/uploads/ssp-debug/ssp-debug.log) without any access controls. This makes it possible for…
AplazadaMedia (6.5)0.20%—Debuggers Studio Marquee Addons FOR ElementorAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through <= 3.8.2.
AplazadaAlta (8.6)0.45%—Tesla Telematics Control UnitAIGoogle Android Debug BridgeAI7/10/202517/6/2026
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port…
AplazadaAlta (8.8)0.45%—DebugAI15/9/202523/9/2026
debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after a phishing attack. Version 4.4.2 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the…
AnalizadaCrítica (9.8)0.47%—Nvidia Nvdebug9/9/202517/6/2026
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure and data tampering.
AnalizadaCrítica (9.8)0.75%—Nvidia Nvdebug9/9/202517/6/2026
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulnerability may lead to information disclosure, denial of service, and data tampering.
AnalizadaCrítica (9.8)0.33%—Nvidia Nvdebug9/9/202517/6/2026
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure and data tampering.
AplazadaAlta (7.2)0.92%—Atec DebugAI4/9/202517/6/2026
The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions up to, and including, 1.2.22. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on…
AplazadaAlta (7.2)0.61%—Atec DebugAI4/9/202517/6/2026
The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This is due to insufficient sanitization when saving the custom log path. This makes it possible for authenticated attackers, with Administrator-level access and…
AplazadaMedia (4.9)0.43%—Atec DebugAI4/9/202517/6/2026
The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to view the contents of files outside of the originally intended directory.
AplazadaCrítica (9.3)7.4%—XdebugAI23/7/202517/6/2026
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugger protocol commands without authentication. An attacker can send a crafted eval…
AnalizadaAlta (7.5)0.33%—Nvidia Nvdebug18/6/202517/6/2026
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of this vulnerability may lead to information disclosure.
AplazadaCrítica (9.8)0.50%—WP Email DebugAI6/6/202517/6/2026
The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled address and then…