Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.11%—Matter Project ChipAIMatter Standard SpecificationAI21/9/202624/9/2026
An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component
Pendiente de análisisMedia (5.3)0.25%—IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI18/9/202618/9/2026
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of…
AplazadaMedia (6.9)0.12%—Standard NotesAIEvernoteAIGoogle KeepAI7/9/20269/9/2026
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and…
Pendiente de análisisAlta (8.7)0.82%—Postgis Address StandardizerAI13/8/202624/9/2026
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a…
Pendiente de análisisMedia (5.6)0.12%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI11/8/202612/8/2026
Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may…
Pendiente de análisisAlta (8.2)0.32%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI11/8/202612/8/2026
Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
Pendiente de análisisMedia (5.9)0.24%—Intel AMTAIIntel Standard ManageabilityAI11/8/202612/8/2026
Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access…
Pendiente de análisisAlta (8.6)0.25%—Wordpress Coding StandardsAI28/7/20269/9/2026
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as…
AnalizadaAlta (8.8)0.49%—Joomshaper Standard PRO Movie Database19/6/202619/8/2026
Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to…
Pendiente de análisisAlta (7.5)0.46%—PHP Standard LibraryAI17/6/202623/6/2026
PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADERS frame, allowing…
AplazadaMedia (5.5)0.63%—Ggerve Coding-standards-mcpAI1/5/202617/6/2026
A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_practices of the file server.py. The manipulation of the argument Language results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. This…
AnalizadaAlta (8.1)0.38%—Anviz Crosschex Standard17/4/202617/6/2026
Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt application traffic.
AnalizadaAlta (7.5)0.34%—Anviz Crosschex Standard17/4/202617/6/2026
Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access.
AnalizadaAlta (7.8)0.15%—Unitree GO2 EDU Plus FirmwareUnitree GO1 PRO FirmwareUnitree GO1 AIR FirmwareUnitree GO2 X Firmware+327/2/202617/6/2026
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. This issue appears…
AplazadaAlta (8.7)0.29%—Intel AMTAIIntel Standard ManageabilityAI10/2/202617/6/2026
Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network…
AplazadaAlta (8.2)0.24%—Intel AMTAIIntel Standard ManageabilityAI10/2/202617/6/2026
Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network…
AplazadaCrítica (9.3)0.70%—Anviz AIM Crosschex StandardAI24/12/202517/6/2026
Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.
AplazadaAlta (8.5)0.12%—QND PremiumAIQND AdvanceAIQND StandardAI11/12/202517/6/2026
QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered, and arbitrary actions may be performed.
AplazadaMedia (5.9)0.33%—Intel AMTAIIntel Standard ManageabilityAI12/8/202517/6/2026
Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via network access.
AplazadaAlta (7.1)0.67%—Intel AMTAIIntel Standard ManageabilityAI12/2/202517/6/2026
Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.
AplazadaMedia (4.6)0.23%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI12/2/202517/6/2026
Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
AnalizadaMedia (5.3)0.58%—Opcfoundation UA .net Standard Stack10/2/202517/6/2026
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
AnalizadaAlta (8.6)0.60%—Opcfoundation UA .net Standard Stack10/2/202517/6/2026
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
AplazadaMedia (5.3)0.13%—Kaspersky Anti-virus SDK FOR WindowsAIKaspersky Security FOR Virtualization Light AgentAIKaspersky Endpoint Security FOR WindowsAIKaspersky Small Office SecurityAI+96/2/202517/6/2026
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security,…
AplazadaAlta (7.5)0.31%—Enituretechnology Standard BOX SizesAI21/1/202517/6/2026
Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Sizes – for WooCommerce: from n/a through <= 1.6.13.