Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.10%—Jetbrains Rider30/9/20262/10/2026
In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
AnalizadaCrítica (10)2.1%—Coderider-kilo Coderider27/3/202617/6/2026
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windows platform,…
AplazadaAlta (8.1)0.58%—Ancorathem PriderAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Prider prider allows PHP Local File Inclusion.This issue affects Prider: from n/a through <= 1.1.3.1.
AplazadaMedia (5.4)0.20%—Merkulove Grider FOR ElementorAI16/12/202517/6/2026
Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grider for Elementor: from n/a through <= 1.0.8.
AnalizadaAlta (7)0.09%—Jetbrains DottraceJetbrains ResharperJetbrains Rider10/11/202525/9/2026
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
AplazadaBaja (1.9)0.14%—Riderlike Fruit Crush-brain APPAI4/8/202517/6/2026
A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.fruitcrush.fun. The manipulation leads to improper export of android application components. It…
AnalizadaAlta (7.5)0.37%—Jetbrains Rider25/4/202517/6/2026
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
AnalizadaAlta (7.8)0.14%—Jetbrains DottraceJetbrains ETW Host ServiceJetbrains ResharperJetbrains Rider28/1/202517/6/2026
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible
ModificadaAlta (7.5)3.8%—Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+910/6/202417/6/2026
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell…
ModificadaMedia (5.3)0.28%—Jetbrains Rider6/2/202417/6/2026
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
ModificadaAlta (7.8)0.20%—Jetbrains Rider3/8/202217/6/2026
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
ModificadaMedia (6.1)0.58%—Uberrider Mediacenter12/7/20229/7/2026
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.
ModificadaAlta (8.8)3.7%—Cardosystems Scala Rider Q3 Firmware24/5/202217/6/2026
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.
ModificadaCrítica (9.8)8.9%—Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaAlta (7.5)0.67%—Jetbrains Rider30/1/202017/6/2026
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
ModificadaAlta (7.8)0.34%—Jetbrains Rider1/10/201917/6/2026
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
ModificadaAlta (8.1)1.7%—Strider-sauce Project Strider-sauce29/5/201817/6/2026
strider-sauce is Sauce Labs / Selenium support for Strider. strider-sauce downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled zip file if the attacker is on the…
ModificadaMedia (4.3)2.8%—Curveriderhq Elgg10/9/200916/6/2026
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)1.4%—Text Rider26/1/200616/6/2026
Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.
ModificadaMedia (5)1.7%—Text Rider26/1/200616/6/2026
Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt.
ModificadaAlta (7.5)1.3%—Asp-rider1/12/200516/6/2026
SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer.
ModificadaAlta (7.5)2.7%—Asp-rider31/12/200416/6/2026
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.