Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.13%—Kilo CodeAI29/9/202630/9/2026
An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
AnalizadaBaja (2.1)0.48%—Kilo Code CLI17/5/202617/6/2026
A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the…
AnalizadaBaja (2.1)0.78%—Kilo Code17/5/202617/6/2026
A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is possible to…
Pendiente de análisisMedia (6.9)0.29%—Wikimedia MediawikiAIWikimedia WikiloveAI7/4/202621/7/2026
Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
AnalizadaCrítica (10)2.1%—Coderider-kilo Coderider27/3/202617/6/2026
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windows platform,…
AplazadaMedia (4.4)0.30%—WikilookupAI21/3/202617/6/2026
The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all versions up to, and including, 1.1.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above,…
AplazadaMedia (6.4)0.20%—WikiloopsAI7/2/202617/6/2026
The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops` shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaCrítica (9.3)0.55%—Kiloview Encoder SeriesAI29/1/202617/6/2026
A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product.
ModificadaAlta (7.5)0.47%—Kiloview E3 Firmware6/11/20255/7/2026
An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.
AplazadaMedia (6.9)0.38%—Wikimedia Mediawiki Wikilove ExtensionAI21/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLove Extension allows Stored XSS.This issue affects Mediawiki - WikiLove Extension: 1.39.
AplazadaCrítica (10)0.24%—Kiloview NDI N30AI13/10/202517/6/2026
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
AplazadaAlta (8.7)0.20%—Kiloview N30AI13/10/202517/6/2026
Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the network
AplazadaBaja (2.1)0.32%—Kilo CodeAI8/10/202517/6/2026
A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch…
ModificadaMedia (5.4)0.24%—Kiloview P1 FirmwareKiloview P2 Firmware2/7/202417/6/2026
A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation, resulting in…
ModificadaCrítica (9.8)0.42%—Kiloview P2 FirmwareKiloview P1 Firmware2/7/202417/6/2026
Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
AplazadaAlta (8.8)2.1%—Kiloview NDIAI21/3/202417/6/2026
An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
AplazadaCrítica (9.8)0.91%—Kiloview NDIAI21/3/202417/6/2026
Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
ModificadaAlta (7.5)0.95%—Kilo Project Kilo20/6/202317/6/2026
Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a denial of service via the editorUpdateRow function in kilo.c.
ModificadaAlta (7.5)2.4%—Kilo Project Kilo8/9/201917/6/2026
Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row.
ModificadaMedia (6.8)2.6%—Canonical Ubuntu LinuxOpenstack IcehouseOpenstack JunoOpenstack Kilo25/6/201517/6/2026
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
ModificadaAlta (10)6.3%—SUN Java 2 Micro EditionAISUN Kilobyte Virtual MachineAI31/12/200416/6/2026
Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code.