Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.53%—Gladysassistant Gladys AssistantAI21/9/202623/9/2026
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a…
AnalizadaCrítica (9.8)0.21%—Oppo Coloros Assistant30/4/202617/6/2026
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
AplazadaAlta (7.1)0.19%—Beaver Builder Wordpress AssistantAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder WordPress Assistant assistant allows Reflected XSS.This issue affects WordPress Assistant: from n/a through <= 1.5.2.
AplazadaAlta (7.2)0.70%—Beaver Builder Wordpress AssistantAI3/3/202517/6/2026
Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1.
ModificadaMedia (6.5)1.0%—Gladysassistant Gladys Assistant7/12/202317/6/2026
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
ModificadaMedia (6.5)0.84%—Gladysassistant Gladys Assistant25/9/202317/6/2026
A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
ModificadaMedia (5.3)0.78%—Samsung S Assistant10/1/202217/6/2026
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
ModificadaBaja (3.3)0.22%—Samsung S Assistant4/3/202117/6/2026
Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.
ModificadaMedia (5.4)0.27%—Wargaming World OF Tanks Assistant9/9/201417/6/2026
The World of Tanks Assistant (aka ru.worldoftanks.mobile) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.