Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.10% | — | Jetbrains Rider | 30/9/2026 | 2/10/2026 | In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | |
| Analizada | Crítica (10) | 2.1% | — | Coderider-kilo Coderider | 27/3/2026 | 17/6/2026 | The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windows platform,… | |
| Aplazada | Alta (8.1) | 0.58% | — | Ancorathem PriderAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Prider prider allows PHP Local File Inclusion.This issue affects Prider: from n/a through <= 1.1.3.1. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Grider FOR ElementorAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grider for Elementor: from n/a through <= 1.0.8. | |
| Analizada | Alta (7) | 0.09% | — | Jetbrains DottraceJetbrains ResharperJetbrains Rider | 10/11/2025 | 25/9/2026 | In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition | |
| Aplazada | Baja (1.9) | 0.14% | — | Riderlike Fruit Crush-brain APPAI | 4/8/2025 | 17/6/2026 | A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.fruitcrush.fun. The manipulation leads to improper export of android application components. It… | |
| Analizada | Alta (7.5) | 0.37% | — | Jetbrains Rider | 25/4/2025 | 17/6/2026 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session | |
| Analizada | Alta (7.8) | 0.14% | — | Jetbrains DottraceJetbrains ETW Host ServiceJetbrains ResharperJetbrains Rider | 28/1/2025 | 17/6/2026 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible | |
| Modificada | Alta (7.5) | 3.8% | — | Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+9 | 10/6/2024 | 17/6/2026 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell… | |
| Modificada | Media (5.3) | 0.28% | — | Jetbrains Rider | 6/2/2024 | 17/6/2026 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible | |
| Modificada | Alta (7.8) | 0.20% | — | Jetbrains Rider | 3/8/2022 | 17/6/2026 | In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution | |
| Modificada | Media (6.1) | 0.58% | — | Uberrider Mediacenter | 12/7/2022 | 9/7/2026 | EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php. | |
| Modificada | Alta (8.8) | 3.7% | — | Cardosystems Scala Rider Q3 Firmware | 24/5/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended. | |
| Modificada | Crítica (9.8) | 8.9% | — | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (7.5) | 0.67% | — | Jetbrains Rider | 30/1/2020 | 17/6/2026 | In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. | |
| Modificada | Alta (7.8) | 0.34% | — | Jetbrains Rider | 1/10/2019 | 17/6/2026 | JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. | |
| Modificada | Alta (8.1) | 1.7% | — | Strider-sauce Project Strider-sauce | 29/5/2018 | 17/6/2026 | strider-sauce is Sauce Labs / Selenium support for Strider. strider-sauce downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the… | |
| Modificada | Media (4.3) | 2.8% | — | Curveriderhq Elgg | 10/9/2009 | 16/6/2026 | Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.4% | — | Text Rider | 26/1/2006 | 16/6/2026 | Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie. | |
| Modificada | Media (5) | 1.7% | — | Text Rider | 26/1/2006 | 16/6/2026 | Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt. | |
| Modificada | Alta (7.5) | 1.3% | — | Asp-rider | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer. | |
| Modificada | Alta (7.5) | 2.7% | — | Asp-rider | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter. |