Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.13% | — | Kilo CodeAI | 29/9/2026 | 30/9/2026 | An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint | |
| Analizada | Baja (2.1) | 0.48% | — | Kilo Code CLI | 17/5/2026 | 17/6/2026 | A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the… | |
| Analizada | Baja (2.1) | 0.78% | — | Kilo Code | 17/5/2026 | 17/6/2026 | A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is possible to… | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | Wikimedia MediawikiAIWikimedia WikiloveAI | 7/4/2026 | 21/7/2026 | Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | |
| Analizada | Crítica (10) | 2.1% | — | Coderider-kilo Coderider | 27/3/2026 | 17/6/2026 | The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windows platform,… | |
| Aplazada | Media (4.4) | 0.30% | — | WikilookupAI | 21/3/2026 | 17/6/2026 | The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all versions up to, and including, 1.1.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above,… | |
| Aplazada | Media (6.4) | 0.20% | — | WikiloopsAI | 7/2/2026 | 17/6/2026 | The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops` shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Kiloview Encoder SeriesAI | 29/1/2026 | 17/6/2026 | A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product. | |
| Modificada | Alta (7.5) | 0.47% | — | Kiloview E3 Firmware | 6/11/2025 | 5/7/2026 | An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component. | |
| Aplazada | Media (6.9) | 0.38% | — | Wikimedia Mediawiki Wikilove ExtensionAI | 21/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLove Extension allows Stored XSS.This issue affects Mediawiki - WikiLove Extension: 1.39. | |
| Aplazada | Crítica (10) | 0.24% | — | Kiloview NDI N30AI | 13/10/2025 | 17/6/2026 | A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246 | |
| Aplazada | Alta (8.7) | 0.20% | — | Kiloview N30AI | 13/10/2025 | 17/6/2026 | Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the network | |
| Aplazada | Baja (2.1) | 0.32% | — | Kilo CodeAI | 8/10/2025 | 17/6/2026 | A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch… | |
| Modificada | Media (5.4) | 0.24% | — | Kiloview P1 FirmwareKiloview P2 Firmware | 2/7/2024 | 17/6/2026 | A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation, resulting in… | |
| Modificada | Crítica (9.8) | 0.42% | — | Kiloview P2 FirmwareKiloview P1 Firmware | 2/7/2024 | 17/6/2026 | Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access. | |
| Aplazada | Alta (8.8) | 2.1% | — | Kiloview NDIAI | 21/3/2024 | 17/6/2026 | An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . | |
| Aplazada | Crítica (9.8) | 0.91% | — | Kiloview NDIAI | 21/3/2024 | 17/6/2026 | Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . | |
| Modificada | Alta (7.5) | 0.95% | — | Kilo Project Kilo | 20/6/2023 | 17/6/2026 | Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a denial of service via the editorUpdateRow function in kilo.c. | |
| Modificada | Alta (7.5) | 2.4% | — | Kilo Project Kilo | 8/9/2019 | 17/6/2026 | Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row. | |
| Modificada | Media (6.8) | 2.6% | — | Canonical Ubuntu LinuxOpenstack IcehouseOpenstack JunoOpenstack Kilo | 25/6/2015 | 17/6/2026 | OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command. | |
| Modificada | Alta (10) | 6.3% | — | SUN Java 2 Micro EditionAISUN Kilobyte Virtual MachineAI | 31/12/2004 | 16/6/2026 | Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code. |