Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

1970 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.09%—Seclore Filesecure Desktop ClientAI25/9/202630/9/2026
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.
AplazadaAlta (7.1)0.25%—Tailored ToolsAI31/8/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
AplazadaAlta (7.1)0.17%—Sublinear-time-solverAIConsciousness-explorerAI25/8/20269/9/2026
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools in src/consciousness-explorer/mcp/server.js pass the attacker-controlled filepath…
AplazadaBaja (2.1)0.37%—Jkawamoto MCP Florence2AI17/8/202620/8/2026
A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init__.py. This manipulation of the argument src causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. It…
AplazadaMedia (5.5)0.47%—Modelcontextprotocol MCP RDF ExplorerAI13/8/202614/8/2026
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The…
AnalizadaCrítica (9.6)0.86%—Microsoft Azure Storage Explorer11/8/202617/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (7.1)0.46%—Huggingface TransformersAIHuggingface IdeficsAIHuggingface FlorenceAIHuggingface GemmaAI+22/8/20263/9/2026
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames…
Pendiente de análisisAlta (7.5)0.15%—Lorex 2K Indoor Wi-fi Security CameraAI13/7/202614/7/2026
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this…
Pendiente de análisisAlta (7.5)0.41%—Lorex 2K Indoor Wi-fi Security CameraAI13/7/202614/7/2026
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. Authentication is not required to exploit this vulnerability. The…
AnalizadaAlta (7.8)0.12%—Synology Hyper Backup Explorer3/6/202622/7/2026
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
Pendiente de análisisAlta (8.2)0.10%—Graph ExplorerAI2/6/202622/7/2026
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
AnalizadaAlta (8.6)0.12%—Draeger Infinity Explorer C700 Firmware1/6/202622/7/2026
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display…
AplazadaBaja (2.1)0.28%—Orthanc Explorer 2AI31/5/202622/7/2026
A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack…
AplazadaAlta (8.6)0.16%—10-strike Network Inventory ExplorerAI23/5/202623/7/2026
10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string with 4188 bytes of…
AplazadaCrítica (9.3)0.26%—SketchupAIMicrosoft Internet ExplorerAI22/5/202623/7/2026
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary…
AplazadaMedia (6.5)0.48%—Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI11/5/202617/6/2026
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were…
AplazadaMedia (5.5)0.59%—Florensiawidjaja BioinformcpAI29/4/202617/6/2026
A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of the component Upload Endpoint. This manipulation of the argument Name causes path traversal. The attack can be…
AplazadaBaja (2.9)0.40%—Collabora KodexplorerAI19/4/202617/6/2026
A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileUpload Endpoint. The manipulation of the argument fileUpload leads to improper authorization. Remote exploitation of the…
AplazadaBaja (2.1)0.36%—Kodcloud KodexplorerAI19/4/202617/6/2026
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has…
AplazadaBaja (2)0.40%—Kodcloud KodexplorerAI19/4/202617/6/2026
A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the…
AplazadaMedia (6.9)0.65%—Kodcloud KodexplorerAI19/4/202617/6/2026
A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted…
AplazadaMedia (5.5)0.72%—Kodcloud KodexplorerAI19/4/202617/6/2026
A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remotely. The exploit…
AplazadaMedia (6.1)0.29%—CodecolorerAI16/4/202617/6/2026
The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AnalizadaMedia (4.3)0.35%—SAP Hana CockpitSAP Hana Database Explorer14/4/202617/6/2026
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
AplazadaMedia (6.9)0.15%—Remote Process ExplorerAI5/4/202624/7/2026
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer,…