Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.53% | — | Gladysassistant Gladys AssistantAI | 21/9/2026 | 23/9/2026 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a… | |
| Analizada | Crítica (9.8) | 0.21% | — | Oppo Coloros Assistant | 30/4/2026 | 17/6/2026 | ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. | |
| Aplazada | Alta (7.1) | 0.19% | — | Beaver Builder Wordpress AssistantAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.2) | 0.70% | — | Beaver Builder Wordpress AssistantAI | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1. | |
| Modificada | Media (6.5) | 1.0% | — | Gladysassistant Gladys Assistant | 7/12/2023 | 17/6/2026 | Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine. | |
| Modificada | Media (6.5) | 0.84% | — | Gladysassistant Gladys Assistant | 25/9/2023 | 17/6/2026 | A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input. | |
| Modificada | Media (5.3) | 0.78% | — | Samsung S Assistant | 10/1/2022 | 17/6/2026 | Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information. | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung S Assistant | 4/3/2021 | 17/6/2026 | Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider. | |
| Modificada | Media (5.4) | 0.27% | — | Wargaming World OF Tanks Assistant | 9/9/2014 | 17/6/2026 | The World of Tanks Assistant (aka ru.worldoftanks.mobile) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |