Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.11% | — | Matter Project ChipAIMatter Standard SpecificationAI | 21/9/2026 | 24/9/2026 | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component | |
| Pendiente de análisis | Media (5.3) | 0.25% | — | IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI | 18/9/2026 | 18/9/2026 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of… | |
| Aplazada | Media (6.9) | 0.12% | — | Standard NotesAIEvernoteAIGoogle KeepAI | 7/9/2026 | 9/9/2026 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and… | |
| Pendiente de análisis | Alta (8.7) | 0.82% | — | Postgis Address StandardizerAI | 13/8/2026 | 24/9/2026 | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a… | |
| Pendiente de análisis | Media (5.6) | 0.12% | — | Intel Active Management TechnologyAIIntel Standard ManageabilityAI | 11/8/2026 | 12/8/2026 | Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may… | |
| Pendiente de análisis | Alta (8.2) | 0.32% | — | Intel Active Management TechnologyAIIntel Standard ManageabilityAI | 11/8/2026 | 12/8/2026 | Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Pendiente de análisis | Media (5.9) | 0.24% | — | Intel AMTAIIntel Standard ManageabilityAI | 11/8/2026 | 12/8/2026 | Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access… | |
| Pendiente de análisis | Alta (8.6) | 0.25% | — | Wordpress Coding StandardsAI | 28/7/2026 | 9/9/2026 | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomshaper Standard PRO Movie Database | 19/6/2026 | 19/8/2026 | Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | PHP Standard LibraryAI | 17/6/2026 | 23/6/2026 | PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADERS frame, allowing… | |
| Aplazada | Media (5.5) | 0.63% | — | Ggerve Coding-standards-mcpAI | 1/5/2026 | 17/6/2026 | A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_practices of the file server.py. The manipulation of the argument Language results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. This… | |
| Analizada | Alta (8.1) | 0.38% | — | Anviz Crosschex Standard | 17/4/2026 | 17/6/2026 | Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt application traffic. | |
| Analizada | Alta (7.5) | 0.34% | — | Anviz Crosschex Standard | 17/4/2026 | 17/6/2026 | Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access. | |
| Analizada | Alta (7.8) | 0.15% | — | Unitree GO2 EDU Plus FirmwareUnitree GO1 PRO FirmwareUnitree GO1 AIR FirmwareUnitree GO2 X Firmware+3 | 27/2/2026 | 17/6/2026 | Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears… | |
| Aplazada | Alta (8.7) | 0.29% | — | Intel AMTAIIntel Standard ManageabilityAI | 10/2/2026 | 17/6/2026 | Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network… | |
| Aplazada | Alta (8.2) | 0.24% | — | Intel AMTAIIntel Standard ManageabilityAI | 10/2/2026 | 17/6/2026 | Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network… | |
| Aplazada | Crítica (9.3) | 0.70% | — | Anviz AIM Crosschex StandardAI | 24/12/2025 | 17/6/2026 | Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data. | |
| Aplazada | Alta (8.5) | 0.12% | — | QND PremiumAIQND AdvanceAIQND StandardAI | 11/12/2025 | 17/6/2026 | QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered, and arbitrary actions may be performed. | |
| Aplazada | Media (5.9) | 0.33% | — | Intel AMTAIIntel Standard ManageabilityAI | 12/8/2025 | 17/6/2026 | Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via network access. | |
| Aplazada | Alta (7.1) | 0.67% | — | Intel AMTAIIntel Standard ManageabilityAI | 12/2/2025 | 17/6/2026 | Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access. | |
| Aplazada | Media (4.6) | 0.23% | — | Intel Active Management TechnologyAIIntel Standard ManageabilityAI | 12/2/2025 | 17/6/2026 | Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access. | |
| Analizada | Media (5.3) | 0.58% | — | Opcfoundation UA .net Standard Stack | 10/2/2025 | 17/6/2026 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints. | |
| Analizada | Alta (8.6) | 0.60% | — | Opcfoundation UA .net Standard Stack | 10/2/2025 | 17/6/2026 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. | |
| Aplazada | Media (5.3) | 0.13% | — | Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+9 | 6/2/2025 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,… | |
| Aplazada | Alta (7.5) | 0.31% | — | Enituretechnology Standard BOX SizesAI | 21/1/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Sizes – for WooCommerce: from n/a through <= 1.6.13. |