Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.53% | — | Davegamble CjsonAI | 10/9/2026 | 10/9/2026 | A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue… | |
| Analizada | Media (6.9) | 0.43% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully… | |
| Analizada | Alta (8.2) | 0.65% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred… | |
| Analizada | Alta (8.7) | 0.70% | — | Davegamble Cjson | 29/7/2026 | 4/8/2026 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the… | |
| Analizada | Media (5.1) | 0.29% | — | Davegamble Cjson | 27/7/2026 | 26/8/2026 | cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based… | |
| Aplazada | Media (4.9) | 0.33% | — | Josevega Woocommerce Bulk Edit Products WP Sheet EditorAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21. | |
| Analizada | Alta (7.5) | 0.52% | — | Vegapuls 6X Firmware | 28/4/2026 | 17/6/2026 | An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes. | |
| Aplazada | Alta (8.1) | 0.52% | — | Ancrathemes VegadaysAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows PHP Local File Inclusion.This issue affects VegaDays: from n/a through <= 1.2.0. | |
| Analizada | Alta (8.7) | 0.95% | — | Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+6 | 24/2/2026 | 17/6/2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the… | |
| Analizada | Crítica (9.3) | 2.7% | — | Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+6 | 24/2/2026 | 17/6/2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access,… | |
| Analizada | Alta (8.7) | 1.0% | — | Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+6 | 24/2/2026 | 17/6/2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data. | |
| Aplazada | Baja (2.1) | 0.27% | — | Isaacwasserman MCP Vegalite ServerAI | 6/2/2026 | 17/6/2026 | A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. The attack may be… | |
| Analizada | Alta (7.4) | 0.44% | — | Beatxp Vega Smartwatch Firmware | 22/1/2026 | 17/6/2026 | An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connection | |
| Analizada | Media (6.1) | 0.23% | — | Vega-functions Project Vega-functions | 5/1/2026 | 17/6/2026 | vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites that allow users to supply untrusted user input, malicious use of an internal function (not part of the public API) could be used to run unintentional javascript (XSS). This issue is fixed in… | |
| Analizada | Crítica (9.3) | 0.51% | — | Vega Project Vega | 5/1/2026 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting two conditions are at risk of arbitrary JavaScript code execution, even if "safe mode" expressionInterpreter is used. First, they use `vega`… | |
| Aplazada | Alta (8.7) | 0.29% | — | VegaAI | 18/12/2025 | 17/6/2026 | due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information. | |
| Aplazada | Alta (8.1) | 0.40% | — | VegaAIVega-expressionAIVega-interpreterAI | 13/11/2025 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 6.2.0, applications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if "safe mode" expressionInterpreter is used. They are vulnerable if they… | |
| Analizada | Crítica (9.8) | 1.9% | — | Dynatrace Activegate Ping Extension | 5/11/2025 | 17/6/2026 | OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. | |
| Aplazada | Media (6.5) | 0.28% | — | Josevega WP Frontend AdminAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Vega WP Frontend Admin display-admin-page-on-frontend allows Stored XSS.This issue affects WP Frontend Admin: from n/a through <= 1.22.7. | |
| Aplazada | Alta (8.6) | 0.28% | — | Vegagrup Software Vega MasterAI | 16/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing. This issue affects Vega Master: from v.1.12.35 through 20250916. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The… | |
| Modificada | Crítica (9.8) | 0.74% | — | Davegamble Cjson | 3/9/2025 | 17/6/2026 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters. | |
| Aplazada | Media (6.5) | 0.21% | — | Jamesdbruner WP VegasAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jamesdbruner WP Vegas vegas-fullscreen-background-slider allows Stored XSS.This issue affects WP Vegas: from n/a through <= 2.2. | |
| Analizada | Media (5.4) | 0.30% | — | Wvega Jsfiddle Shortcode | 15/5/2025 | 17/6/2026 | The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.3) | 0.51% | — | VegaAIVega-functionsAIVega-liteAI | 27/3/2025 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 5.32.0, corresponding to vega-functions prior to version 5.17.0, users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs,… | |
| Analizada | Media (5.3) | 0.34% | — | Vega-functions Project Vega-functionsVega Project Vega | 27/3/2025 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not meant to be supported. The issue… |