Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

1895 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.17%—Sublinear-time-solverAIConsciousness-explorerAI25/8/20269/9/2026
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools in src/consciousness-explorer/mcp/server.js pass the attacker-controlled filepath…
AplazadaMedia (5.5)0.47%—Modelcontextprotocol MCP RDF ExplorerAI13/8/202614/8/2026
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The…
AnalizadaCrítica (9.6)0.86%—Microsoft Azure Storage Explorer11/8/202617/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.12%—Synology Hyper Backup Explorer3/6/202622/7/2026
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
Pendiente de análisisAlta (8.2)0.10%—Graph ExplorerAI2/6/202622/7/2026
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
AnalizadaAlta (8.6)0.12%—Draeger Infinity Explorer C700 Firmware1/6/202622/7/2026
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display…
AplazadaBaja (2.1)0.28%—Orthanc Explorer 2AI31/5/202622/7/2026
A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack…
AplazadaAlta (8.6)0.16%—10-strike Network Inventory ExplorerAI23/5/202623/7/2026
10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string with 4188 bytes of…
AplazadaCrítica (9.3)0.26%—SketchupAIMicrosoft Internet ExplorerAI22/5/202623/7/2026
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary…
AplazadaMedia (6.5)0.48%—Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI11/5/202617/6/2026
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were…
AplazadaBaja (2.9)0.40%—Collabora KodexplorerAI19/4/202617/6/2026
A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileUpload Endpoint. The manipulation of the argument fileUpload leads to improper authorization. Remote exploitation of the…
AplazadaBaja (2.1)0.36%—Kodcloud KodexplorerAI19/4/202617/6/2026
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has…
AplazadaBaja (2)0.40%—Kodcloud KodexplorerAI19/4/202617/6/2026
A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the…
AplazadaMedia (6.9)0.65%—Kodcloud KodexplorerAI19/4/202617/6/2026
A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted…
AplazadaMedia (5.5)0.72%—Kodcloud KodexplorerAI19/4/202617/6/2026
A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remotely. The exploit…
AnalizadaMedia (4.3)0.35%—SAP Hana CockpitSAP Hana Database Explorer14/4/202617/6/2026
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
AplazadaMedia (6.9)0.15%—Remote Process ExplorerAI5/4/202624/7/2026
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer,…
AnalizadaAlta (8.1)0.43%—Pab1it0 Azure Data Explorer MCP Server27/3/202617/6/2026
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP…
AnalizadaAlta (8.6)0.22%—Rttsoftware PDF Explorer26/3/202617/6/2026
PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields…
AplazadaMedia (6.9)0.13%—Spotie Internet Explorer Password RecoveryAI11/3/202617/6/2026
SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a…
AnalizadaCrítica (9.3)0.96%—Xiaomi Fileexplorer11/3/202614/7/2026
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows…
AnalizadaAlta (7.5)1.0%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.00%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.72%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.70%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.