Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 1.2% | — | Jhen0409 React-native-debuggerAI | 24/9/2026 | 25/9/2026 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack… | |
| Aplazada | Baja (2.1) | 0.52% | — | Debugmcp Mcp-debuggerAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted… | |
| Aplazada | Alta (8.8) | 0.61% | — | Debugger TroubleshooterAI | 30/3/2026 | 17/6/2026 | The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_troubleshoot_simulate_user cookie value directly as a user ID without any cryptographic validation or authorization checks.… | |
| Aplazada | Crítica (9.1) | 0.51% | — | Slajerek RetrodebuggerAI | 24/3/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72. | |
| Aplazada | Alta (8.5) | 0.13% | — | Httpdebugger PROAI | 15/1/2026 | 17/6/2026 | HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and gain elevated access to the system. | |
| Aplazada | Media (6.5) | 0.20% | — | Debuggers Studio Marquee Addons FOR ElementorAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through <= 3.8.2. | |
| Aplazada | Media (5.4) | 0.19% | — | Immunity DebuggerAI | 17/3/2025 | 17/6/2026 | Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, due to the lack of proper boundary checking. | |
| Aplazada | Media (5.5) | 0.27% | — | Immunity INC Immunity DebuggerAI | 13/2/2025 | 17/6/2026 | A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size. | |
| Aplazada | Media (6.5) | 0.23% | — | Debuggers Studio SaaspricingAI | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio SaasPricing saaspricing allows DOM-Based XSS.This issue affects SaasPricing: from n/a through <= 1.2.4. | |
| Modificada | Alta (8.8) | 0.26% | — | Template Debugger Project Template Debugger | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <= 3.1.2 versions. | |
| Modificada | Media (5.3) | 0.27% | — | Madefornet Http Debugger | 5/7/2023 | 17/6/2026 | In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access. | |
| Modificada | Media (5.5) | 0.19% | — | Edb-debugger Project Edb-debugger | 4/4/2023 | 17/6/2026 | An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Modificada | Crítica (9.1) | 1.3% | — | Chameleon Mini Live Debugger Project Chameleon Mini Live Debugger | 28/8/2020 | 17/6/2026 | Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory. | |
| Modificada | Crítica (9.6) | 4.6% | — | Debian LinuxOpenocd Open On-chip Debugger | 16/1/2018 | 17/6/2026 | Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site. | |
| Modificada | Media (5) | 1.4% | — | Asial Monaca Debugger | 16/11/2012 | 16/6/2026 | The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application. | |
| Modificada | Media (6.9) | 0.39% | — | Debian Mono-debugger | 20/10/2010 | 16/6/2026 | The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Alta (7.2) | 0.58% | — | GNU Data Display Debugger | 31/12/2002 | 16/6/2026 | Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE. | |
| Modificada | Alta (7.2) | 0.36% | — | SGI Workshop Debugger AND Performance Tools | 20/6/2000 | 16/6/2026 | Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files. |