Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.46% | — | Mayan-edms Mayan Edms | 15/12/2025 | 17/6/2026 | A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes open redirect. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 4.10.2 is sufficient to resolve this… | |
| Analizada | Baja (2.1) | 0.46% | — | Mayan-edms Mayan Edms | 14/12/2025 | 17/6/2026 | A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this… | |
| Aplazada | Alta (7.5) | 0.36% | — | Maya Business Paymaya-checkout-for-woocommerceAI | 20/8/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business paymaya-checkout-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maya Business: from n/a through <= 1.2.0. | |
| Modificada | Media (6.6) | 0.20% | — | Autodesk MayaAutodesk Universal Scene Description | 11/6/2025 | 17/6/2026 | A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption. | |
| Modificada | Crítica (9.8) | 0.63% | — | Mayanets E-commerce | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mAyaNet E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 1.1. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. | |
| Modificada | Alta (7.8) | 0.25% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 23/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk Maya USD | 17/4/2023 | 17/6/2026 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerability which may result in code execution. | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk Maya USD | 17/4/2023 | 17/6/2026 | A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerability which may result in code execution. | |
| Modificada | Alta (7.8) | 0.30% | — | Autodesk Maya USD | 17/4/2023 | 17/6/2026 | A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution. | |
| Modificada | Media (5.4) | 0.54% | — | Mayan-edms Mayan Edms | 7/2/2023 | 17/6/2026 | An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system. | |
| Modificada | Alta (7.8) | 0.29% | — | Autodesk Maya | 19/12/2022 | 17/6/2026 | A maliciously crafted X_B file when parsed through Autodesk Maya 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution. | |
| Modificada | Alta (7.1) | 0.28% | — | Autodesk Maya | 19/12/2022 | 17/6/2026 | Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Crítica (9.8) | 1.4% | — | Tejimaya Opwebapiplugin | 7/2/2020 | 16/6/2026 | opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities | |
| Modificada | Crítica (9.1) | 2.2% | — | Tejimaya Openpne | 24/1/2020 | 16/6/2026 | OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability | |
| Modificada | Media (6.1) | 1.2% | — | Mayan-edms Mayan Edms | 3/9/2018 | 17/6/2026 | An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. | |
| Modificada | Media (6.1) | 1.3% | — | Mayan-edms Mayan Edms | 3/9/2018 | 17/6/2026 | An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. | |
| Modificada | Media (6.1) | 1.4% | — | Mayan-edms Mayan Edms | 3/9/2018 | 17/6/2026 | An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. | |
| Modificada | Media (4.6) | 0.22% | — | Huawei Maya-l02 FirmwareHuawei Vky-l09 FirmwareHuawei Vky-l29 FirmwareHuawei Vicky-al00a Firmware+2 | 22/11/2017 | 17/6/2026 | Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162 versions,earlier than Victoria-AL00AC00B167 versions,earlier than… | |
| Modificada | Baja (3.5) | 3.5% | — | Mayan-edms Mayan Edms | 27/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2) title of a source in a Staging folder, (3) Name field in a bootstrap setup, or Title field in a (4)… | |
| Modificada | Alta (7.5) | 1.5% | — | Tejimaya Openpne | 24/1/2014 | 16/6/2026 | The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and… | |
| Modificada | Media (4.3) | 1.1% | — | Tejimaya Openpne | 17/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme." | |
| Modificada | Media (5.8) | 1.1% | — | Tejimaya Openpne | 23/3/2010 | 16/6/2026 | The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing. | |
| Modificada | Alta (9.3) | 4.4% | — | Autodesk Alias Wavefront MayaAutodesk Maya | 24/11/2009 | 16/6/2026 | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes." |