Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
253 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | — | — | Avez Electronics Learning Management SystemAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | |
| En análisis | Alta (7.8) | 0.09% | — | ElectronAI | 29/9/2026 | 2/10/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write… | |
| En análisis | Alta (8.3) | 0.45% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing… | |
| En análisis | Alta (7.4) | 0.21% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but… | |
| En análisis | Alta (8.2) | 0.27% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level… | |
| En análisis | Alta (8.2) | 0.15% | — | ElectronAI | 29/9/2026 | 30/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Karel Electronic Industry AND Trade KarelipsAI | 22/9/2026 | 22/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Alta (7.1) | 0.48% | — | Jitsi Electron-sdkAI | 16/9/2026 | 16/9/2026 | @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbnails at arbitrary… | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Aplazada | Media (4.3) | 0.18% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI | 9/9/2026 | 9/9/2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2. | |
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… | |
| Aplazada | Media (6.1) | 0.25% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and… | |
| Aplazada | Media (5.3) | 0.51% | — | Nousresearch Hermes-agentAIElectronAI | 3/9/2026 | 3/9/2026 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely.… | |
| Aplazada | Alta (7) | 0.17% | — | Electron-builderAIMicrosoft Windows InstallerAI | 30/8/2026 | 1/9/2026 | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that… | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAIMind ElixirAIElectronAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed a… | |
| Aplazada | Alta (8.3) | 0.41% | — | StreambertAIElectronAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs… | |
| Aplazada | Alta (8.8) | 0.20% | — | StreambertAIElectronAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler… | |
| Aplazada | Alta (7.8) | 0.22% | — | Super ProductivityAIElectronAI | 18/8/2026 | 18/9/2026 | Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC.EXEC channel and executes it with child_process.exec(). The electron/preload.ts… | |
| Aplazada | Alta (8.1) | 0.49% | — | TabbyAITabby-sshAITabby-electronAI | 10/8/2026 | 9/9/2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary… | |
| Pendiente de análisis | Media (5.6) | 0.11% | — | Elan Microelectronics Corp Elan Smart-padAIElan Microelectronics Corp Etd.sysAIElan Microelectronics Corp Etdsmbus.sysAI | 6/8/2026 | 3/9/2026 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where… | |
| En análisis | Media (5.4) | 0.44% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered… | |
| En análisis | Media (6.9) | 0.18% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the… | |
| En análisis | Media (5.4) | 0.58% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks… | |
| En análisis | Media (5.7) | 0.55% | — | ElectronAI | 5/8/2026 | 8/9/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their… |