Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Jane-xiaoer Skill-vision-controlAI | 9/8/2026 | 13/8/2026 | A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project… | |
| Aplazada | Alta (8.7) | 0.54% | — | Loytec LIP Me201cAILoytec L INXAILoytec L GateAILoytec L ROCAI+4 | 24/7/2026 | 27/7/2026 | Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet… | |
| Aplazada | Media (6.6) | 0.54% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request with a large OID… | |
| Aplazada | Baja (3.8) | 0.16% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+4 | 24/7/2026 | 27/7/2026 | Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long… | |
| Aplazada | Alta (8.4) | 0.19% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field. | |
| Aplazada | Crítica (9.2) | 0.18% | — | Loytec L-inxAILoytec L-gateAILoytec L-rocAILoytec L-iobAI+3 | 24/7/2026 | 27/7/2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on… | |
| Aplazada | Alta (8.4) | 0.15% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+5 | 24/7/2026 | 27/7/2026 | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand. | |
| Aplazada | Alta (8.7) | 0.61% | — | Loytec Lip-me201cAILoytec L-inxAILoytec L-gateAILoytec L-rocAI+4 | 24/7/2026 | 27/7/2026 | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft,… | |
| Aplazada | Media (6.4) | 0.16% | — | Eaglevisionit Rise BlocksAI | 25/2/2026 | 17/6/2026 | The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.22% | — | Jhainey Milevis DropifyAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhainey Milevis Dropify wc-dropi-integration allows Reflected XSS.This issue affects Dropify: from n/a through <= 4.7.2. | |
| Aplazada | Crítica (9.8) | 0.35% | — | Callvision Healthcare Callvision Emergency CodeAI | 7/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0. | |
| Modificada | Media (5.4) | 0.34% | — | Eaglevisionit Rise Blocks | 12/2/2025 | 17/6/2026 | The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the titleTag parameter in all versions up to, and including, 3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.49% | — | Gleamtech Filevista | 7/2/2025 | 17/6/2026 | Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication… | |
| Analizada | Media (6.3) | 3.2% | — | Gleamtech Filevista | 7/2/2025 | 17/6/2026 | Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files. | |
| Aplazada | Alta (7.1) | 0.27% | — | Michael Visser Jigoshop Store ToolkitAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Visser Jigoshop – Store Toolkit jigoshop-store-toolkit allows Reflected XSS.This issue affects Jigoshop – Store Toolkit: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.32% | — | Yellopencil Visual CSS Style EditorAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YellowPencil YellowPencil Visual CSS Style Editor yellow-pencil-visual-theme-customizer allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through <= 7.6.4. | |
| Aplazada | Media (4.3) | 0.29% | — | Clavister E10AIClavister E80AI | 2/4/2024 | 17/6/2026 | A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Baja (2.4) | 0.49% | — | Clavister E10AIClavister E80AI | 1/4/2024 | 17/6/2026 | A vulnerability has been found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This vulnerability affects unknown code of the file /?Page=Node&OBJ=/System/AdvancedSettings/DeviceSettings/MiscSettings of the component Misc Settings Page. The manipulation of the argument… | |
| Modificada | Alta (8.8) | 0.22% | — | Eaglevisionit Rise Blocks | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rise Themes Rise Blocks – A Complete Gutenberg Page Builder.This issue affects Rise Blocks – A Complete Gutenberg Page Builder: from n/a through 3.1. | |
| Modificada | Media (5.4) | 0.54% | — | Remyandrade School Visitor LOG E-book | 22/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester School Visitor Log e-Book 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file log-book.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.47% | — | Eaglevisionit Evision Responsive Column Layout Shortcodes | 6/3/2023 | 17/6/2026 | The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.3) | 1.4% | — | Chainerrl-visualizer | 11/7/2022 | 17/6/2026 | The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.8) | 7.6% | — | We-con Levistudiou | 14/1/2022 | 17/6/2026 | WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code. | |
| Modificada | Alta (7.8) | 8.6% | — | We-con Levistudiou | 14/1/2022 | 17/6/2026 | WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. | |
| Modificada | Alta (7.8) | 2.7% | — | We-con Levistudiou | 13/12/2021 | 17/6/2026 | WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to multiple stack-based buffer overflow instances while parsing project files, which may allow an attacker to execute arbitrary code. |