Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.92% | ⚠ Explotación activa | Connectwise Screenconnect | 8/9/2026 | 12/9/2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. | |
| Pendiente de análisis | Alta (7.3) | 0.29% | — | Drupal ScreenshotAI | 2/9/2026 | 2/9/2026 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | |
| Pendiente de análisis | Alta (7.3) | 0.29% | — | Drupal ScreenshotAI | 2/9/2026 | 2/9/2026 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | |
| Aplazada | Media (6.5) | 0.47% | — | Fullscreen GalleriaAI | 16/8/2026 | 20/8/2026 | The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (4.7) | 0.24% | — | Connectwise Screenconnect | 10/6/2026 | 18/8/2026 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens. | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle Financial Services Customer Screening | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.1.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience ManagerAdobe Experience Manager Screens | 14/4/2026 | 28/8/2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires… | |
| Aplazada | Baja (2.1) | 2.4% | — | Moussaabbadla Code-screenshot-mcpAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor… | |
| Analizada | Alta (7.8) | 0.20% | — | Screentogif | 20/3/2026 | 17/6/2026 | ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the Windows System32 directory, allowing arbitrary… | |
| Pendiente de análisis | Crítica (9) | 0.28% | — | Connectwise ScreenconnectAI | 17/3/2026 | 9/7/2026 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE. | |
| Aplazada | Alta (7.1) | 0.30% | — | Lambertgroup Image AND Video Fullscreen BackgroundAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullscreen_fullwidth_slider allows Reflected XSS.This issue affects Image&Video FullScreen Background: from n/a through <= 1.6.7. | |
| Analizada | Media (5.3) | 0.15% | — | Connectwise Screenconnect | 18/12/2025 | 17/6/2026 | In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at rest; however, an… | |
| Analizada | Crítica (9.1) | 0.37% | — | Connectwise Screenconnect | 11/12/2025 | 17/6/2026 | In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the… | |
| Aplazada | Alta (8.5) | 0.31% | — | Lambertgroup Image AND Video Fullscreen BackgroundAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullscreen_fullwidth_slider allows SQL Injection.This issue affects Image&Video FullScreen Background: from n/a through <= 1.6.7. | |
| Analizada | Alta (8.1) | 1.6% | — | Luotengyuan Myscreentools | 17/11/2025 | 17/6/2026 | MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing them to cmd.exe, allowing attackers to execute arbitrary system commands with the privileges of the user running the application.… | |
| Aplazada | Media (4.3) | 0.12% | — | WP Global Screen OptionsAI | 4/11/2025 | 17/6/2026 | The WP Global Screen Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing nonce validation on the `updatewpglobalscreenoptions` action handler. This makes it possible for unauthenticated attackers to modify global screen options for… | |
| Analizada | Media (6.8) | 0.19% | — | Deltaww Diascreen | 3/10/2025 | 17/6/2026 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Analizada | Media (6.8) | 0.16% | — | Deltaww Diascreen | 3/10/2025 | 17/6/2026 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Analizada | Media (6.8) | 0.16% | — | Deltaww Diascreen | 3/10/2025 | 17/6/2026 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Analizada | Media (6.8) | 0.16% | — | Deltaww Diascreen | 3/10/2025 | 17/6/2026 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Aplazada | Media (6.8) | 0.46% | — | Crestron Touchscreens X70AI | 9/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traversal.This issue affects TOUCHSCREENS x70: from 3.000.0110.001 before 3.001.0031.001. Confirmed Affected Hardware: TSW-760, TSW-1060 Confirmed Affected Firmware: 3.002.1061… | |
| Aplazada | Alta (8.6) | 0.37% | — | Crestron Touchscreens X70AICrestron Tsw-x70AICrestron Tsw-x60AICrestron Tst-1080AI+9 | 3/9/2025 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid… |