Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Parallax Section BlockAI | 1/10/2026 | 1/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Parallax Filament-commentsAI | 14/9/2026 | 24/9/2026 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other users viewing those comments, including… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Parallels DesktopAI | 14/9/2026 | 18/9/2026 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Jenkins Parameterized Remote Trigger PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Pendiente de análisis | Alta (8.8) | 0.83% | — | Jenkins File Parameter PluginAI | 2/9/2026 | 3/9/2026 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution. | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens ParasolidAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Parameterized Remote TriggerAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Alta (7.3) | 0.09% | — | Eparakstiis EparakstisajsAI | 3/8/2026 | 1/9/2026 | eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier… | |
| Aplazada | Crítica (9) | 0.67% | — | Facturone Para Woocommerce CON VerifactuAI | 27/7/2026 | 27/7/2026 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible… | |
| Aplazada | Media (5.3) | 0.33% | — | DulwichAIParamikoAI | 15/7/2026 | 16/7/2026 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. | |
| Analizada | Media (6.5) | 0.27% | — | Md-systems Paragraphs | 10/7/2026 | 21/7/2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. | |
| Analizada | Media (6.5) | 0.27% | — | Md-systems Paragraphs | 10/7/2026 | 21/7/2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins GIT Parameter | 24/6/2026 | 26/6/2026 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata. | |
| Pendiente de análisis | Baja (3.4) | 0.13% | — | ParamikoAI | 6/5/2026 | 24/7/2026 | In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. | |
| Aplazada | Media (6.5) | 0.33% | — | Parani M10 Motorcycle IntercomAI | 13/4/2026 | 17/6/2026 | An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of Service (DoS) via supplying crafted RFCOMM frames. | |
| Modificada | Media (6.1) | 0.40% | — | Parall Jspdf | 18/3/2026 | 18/8/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be exploited in the following scenario: the… | |
| Modificada | Media (6.5) | 0.62% | — | Parall Jspdf | 18/3/2026 | 18/8/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF… | |
| Modificada | Media (6.1) | 0.39% | — | Kashipara Society Management System Portal | 23/2/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POST HTTP request,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Realvirtualmx Rvcfdi Para WoocommerceAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realvirtualmx RVCFDI para Woocommerce rvcfdi-para-woocommerce allows Reflected XSS.This issue affects RVCFDI para Woocommerce: from n/a through <= 8.1.8. | |
| Modificada | Alta (8.1) | 0.63% | — | Parall Jspdf | 19/2/2026 | 18/8/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following property, a user can inject arbitrary PDF… | |
| Modificada | Alta (8.8) | 0.80% | — | Parall Jspdf | 19/2/2026 | 18/8/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious actions or alter… | |
| Modificada | Alta (8.7) | 0.92% | — | Parall Jspdf | 19/2/2026 | 18/8/2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage` method, a user can provide a harmful GIF file that results in out of memory… |