Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)——Gspeech TTSAI2/10/20262/10/2026
The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaAlta (8.8)0.76%—Nvidia Nemo Speech22/9/202629/9/2026
NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.
AnalizadaAlta (7.8)0.39%—Nvidia Nemo Speech22/9/202629/9/2026
NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.
AnalizadaAlta (7.8)0.25%—Nvidia Nemo Speech22/9/202625/9/2026
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
AnalizadaAlta (7.8)0.35%—Nvidia Nemo Speech22/9/202625/9/2026
NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data…
AnalizadaAlta (7.8)0.35%—Nvidia Nemo Speech22/9/202625/9/2026
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
AplazadaAlta (8.7)0.46%—SpeechbrainAI27/8/202624/9/2026
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious…
AplazadaMedia (6.5)0.22%—LQD Liquid Speech BalloonAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
ModificadaAlta (8.8)0.37%—IBM Watson Speech Services Cartridge22/6/202623/7/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
AplazadaAlta (7.5)0.34%—Mementor Text TO Speech FOR WPAI4/4/202621/7/2026
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TTS_Remote_Telemetry`…
AplazadaMedia (4.9)0.41%—Gspeech TTSAI18/10/202517/6/2026
The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' parameter in all versions up to, and including, 3.17.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaMedia (4.3)0.20%—Trinityaudio Text TO SpeechAI4/10/202517/6/2026
The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.20.2. This is due to missing or incorrect nonce validation in the '/admin/inc/post-management.php' file. This makes it possible for…
AplazadaMedia (4.3)0.24%—Azizul Hasan Text TO Speech TTS AccessibilityAI22/9/202517/6/2026
Missing Authorization vulnerability in Azizul Hasan Text To Speech TTS Accessibility text-to-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Text To Speech TTS Accessibility: from n/a through <= 1.9.30.
AplazadaMedia (6.5)0.31%—Elliot Sowersby AI Text TO SpeechAI17/4/202517/6/2026
Missing Authorization vulnerability in Elliot Sowersby / RelyWP AI Text to Speech ai-text-to-speech allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Text to Speech: from n/a through <= 3.0.3.
AplazadaMedia (4.6)0.40%—Globitel KSA SpeechlogAI14/5/202417/6/2026
Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.
AplazadaAlta (7.5)0.62%—Globitel KSA SpeechlogAI14/5/202417/6/2026
Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.
ModificadaAlta (8.8)0.46%—LQD Liquid Speech Balloon10/5/202317/6/2026
Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of a user and to perform unintended operations by having a user view a malicious page.
ModificadaMedia (5.4)0.62%—Responsivevoice Text TO Speech6/2/202317/6/2026
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.5)0.86%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs26/12/202217/6/2026
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
AnalizadaCrítica (9.8)100%⚠ Explotación activaVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaAlta (7.5)0.90%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.
ModificadaAlta (7.5)0.64%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
ModificadaAlta (7.5)0.63%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
ModificadaAlta (7.5)0.56%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information.
ModificadaCrítica (9.8)0.92%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.