Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.40% | — | Jwsthemes LovedateAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects LoveDate: from n/a through < 3.8.6. | |
| Modificada | Alta (8.6) | 0.49% | — | Semantic-machines Veda | 13/1/2026 | 5/7/2026 | An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints. | |
| Aplazada | Alta (8.8) | 0.53% | — | Semantic-machines VedaAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Semantic-machines VedaAI | 5/3/2025 | 17/6/2026 | The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Alta (8.6) | 0.26% | — | Airveda Pm2.5 Pm10 Monitor Firmware | 12/8/2024 | 17/6/2026 | This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful exploitation of this vulnerability could allow the… | |
| Aplazada | Baja (3.8) | 0.14% | — | Livedata Maintenance ServerAI | 5/3/2024 | 17/6/2026 | Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue… | |
| Modificada | Media (5.3) | 0.76% | — | Corveda Phpsandbox | 19/12/2023 | 17/6/2026 | A vulnerability was found in Corveda PHPSandbox 1.3.4 and classified as critical. Affected by this issue is some unknown functionality of the component String Handler. The manipulation leads to protection mechanism failure. The attack may be launched remotely. Upgrading to version 1.3.5 is able to address this issue.… | |
| Modificada | Alta (9.3) | 4.3% | — | Interactivedata Esignal | 16/9/2011 | 16/6/2026 | Untrusted search path vulnerability in eSignal 10.6.2425.1208, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse JRS_UT.dll that is located in the same folder as a .quo (QUOTE) file. NOTE: the provenance of… | |
| Modificada | Alta (10) | 56% | — | Interactivedata Esignal | 16/9/2011 | 16/6/2026 | WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (2) a long Font->FaceName field (aka FaceName element), which… | |
| Modificada | Alta (10) | 8.4% | — | Livedata Protocol Server | 3/5/2007 | 16/6/2026 | Heap-based buffer overflow in LiveData Protocol Server 5.00.045, and other versions before update 500062 (5.00.062), allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request for a WSDL file that causes a negative length to be used in a strncpy call. | |
| Modificada | Alta (7.8) | 3.7% | — | Livedata Iccp ServerLivedata Maintenance ServerLivedata Protocol Server | 3/5/2007 | 16/6/2026 | Unspecified vulnerability in LiveData Server before 5.00.62 allows remote attackers to cause a denial of service (exit) via crafted Connection-Oriented Transport Protocol (COTP) packets. | |
| Modificada | Alta (7.5) | 4.7% | — | Livedata Iccp Server | 19/5/2006 | 16/6/2026 | Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets. |