Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.53%—Davegamble CjsonAI10/9/202610/9/2026
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue…
AnalizadaMedia (6.9)0.43%—Davegamble Cjson29/7/20264/8/2026
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully…
AnalizadaAlta (8.2)0.65%—Davegamble Cjson29/7/20264/8/2026
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred…
AnalizadaAlta (8.7)0.70%—Davegamble Cjson29/7/20264/8/2026
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the…
AnalizadaMedia (5.1)0.29%—Davegamble Cjson27/7/202626/8/2026
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based…
AplazadaMedia (4.9)0.33%—Josevega Woocommerce Bulk Edit Products WP Sheet EditorAI13/7/202613/7/2026
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.
AnalizadaAlta (7.5)0.52%—Vegapuls 6X Firmware28/4/202617/6/2026
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.
AplazadaAlta (8.1)0.52%—Ancrathemes VegadaysAI25/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows PHP Local File Inclusion.This issue affects VegaDays: from n/a through <= 1.2.0.
AnalizadaAlta (8.7)0.95%—Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+624/2/202617/6/2026
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the…
AnalizadaCrítica (9.3)2.7%—Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+624/2/202617/6/2026
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access,…
AnalizadaAlta (8.7)1.0%—Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+624/2/202617/6/2026
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.
AplazadaBaja (2.1)0.27%—Isaacwasserman MCP Vegalite ServerAI6/2/202617/6/2026
A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. The attack may be…
AnalizadaAlta (7.4)0.44%—Beatxp Vega Smartwatch Firmware22/1/202617/6/2026
An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connection
AnalizadaMedia (6.1)0.23%—Vega-functions Project Vega-functions5/1/202617/6/2026
vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites that allow users to supply untrusted user input, malicious use of an internal function (not part of the public API) could be used to run unintentional javascript (XSS). This issue is fixed in…
AnalizadaCrítica (9.3)0.51%—Vega Project Vega5/1/202617/6/2026
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting two conditions are at risk of arbitrary JavaScript code execution, even if "safe mode" expressionInterpreter is used. First, they use `vega`…
AplazadaAlta (8.7)0.29%—VegaAI18/12/202517/6/2026
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
AplazadaAlta (8.1)0.40%—VegaAIVega-expressionAIVega-interpreterAI13/11/202517/6/2026
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 6.2.0, applications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if "safe mode" expressionInterpreter is used. They are vulnerable if they…
AnalizadaCrítica (9.8)1.9%—Dynatrace Activegate Ping Extension5/11/202517/6/2026
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
AplazadaMedia (6.5)0.28%—Josevega WP Frontend AdminAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Vega WP Frontend Admin display-admin-page-on-frontend allows Stored XSS.This issue affects WP Frontend Admin: from n/a through <= 1.22.7.
AplazadaAlta (8.6)0.28%—Vegagrup Software Vega MasterAI16/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing. This issue affects Vega Master: from v.1.12.35 through 20250916. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The…
ModificadaCrítica (9.8)0.74%—Davegamble Cjson3/9/202517/6/2026
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
AplazadaMedia (6.5)0.21%—Jamesdbruner WP VegasAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jamesdbruner WP Vegas vegas-fullscreen-background-slider allows Stored XSS.This issue affects WP Vegas: from n/a through <= 2.2.
AnalizadaMedia (5.4)0.30%—Wvega Jsfiddle Shortcode15/5/202517/6/2026
The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (5.3)0.51%—VegaAIVega-functionsAIVega-liteAI27/3/202517/6/2026
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 5.32.0, corresponding to vega-functions prior to version 5.17.0, users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs,…
AnalizadaMedia (5.3)0.34%—Vega-functions Project Vega-functionsVega Project Vega27/3/202517/6/2026
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not meant to be supported. The issue…