Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.38% | — | RTI Connext ProfessionalAI | 22/9/2026 | 23/9/2026 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1. | |
| Pendiente de análisis | Crítica (10) | 0.31% | — | RTI Connext ProfessionalAI | 22/9/2026 | 23/9/2026 | Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before… | |
| Pendiente de análisis | Alta (7.3) | 0.08% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*. | |
| Pendiente de análisis | Crítica (9.2) | 0.21% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6. | |
| Pendiente de análisis | Media (6.9) | 0.25% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6. | |
| Pendiente de análisis | Alta (8.7) | 0.25% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from… | |
| Pendiente de análisis | Alta (8.3) | 0.26% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.3 before 5.2.*. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | RTI Connext ProfessionalAI | 22/9/2026 | 22/9/2026 | Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6. | |
| Aplazada | Media (6.1) | 0.23% | — | Husky Products Filter ProfessionalAI | 11/9/2026 | 11/9/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which… | |
| Aplazada | Media (6.5) | 0.22% | — | Thingsboard Professional EditionAI | 26/8/2026 | 9/9/2026 | A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation… | |
| Modificada | Alta (8.8) | 0.42% | — | RTI Connext Professional | 17/6/2026 | 22/9/2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.3, from 6.1.2 before 6.1.*. | |
| Modificada | Crítica (9.2) | 0.33% | — | RTI Connext Professional | 17/6/2026 | 22/9/2026 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*. | |
| Modificada | Media (6.1) | 0.47% | — | RTI Connext Professional | 17/6/2026 | 22/9/2026 | Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*. | |
| Modificada | Media (6) | 0.37% | — | RTI Connext Professional | 17/6/2026 | 22/9/2026 | Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*. | |
| Modificada | Media (4.8) | 0.31% | — | RTI Connext Professional | 17/6/2026 | 22/9/2026 | Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*. | |
| Modificada | Crítica (9.2) | 0.19% | — | RTI Connext Professional | 17/6/2026 | 22/9/2026 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from… | |
| Aplazada | Media (4.3) | 0.37% | — | FOX Currency Switcher ProfessionalAI | 28/5/2026 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled… | |
| Aplazada | Alta (8.6) | 0.18% | — | Flash Slideshow Maker ProfessionalAI | 25/5/2026 | 24/7/2026 | Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog… | |
| Aplazada | Alta (8.6) | 0.18% | — | Socusoft DVD Photo Slideshow ProfessionalAI | 25/5/2026 | 23/7/2026 | SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed payload containing… | |
| Aplazada | Alta (8.1) | 0.50% | — | FOX Currency Switcher ProfessionalAI | 15/5/2026 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Baja (2) | 0.41% | — | Codelibs FessAI | 9/5/2026 | 24/7/2026 | A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java of the component JSP File Handler. The manipulation of the argument content results in code injection. The attack may be performed from… | |
| Pendiente de análisis | Media (6.8) | 0.28% | — | Hikvision Hikcentral ProfessionalAI | 9/5/2026 | 25/7/2026 | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. |