Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Bobbingwide OIKAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions. | |
| Analizada | Alta (7.5) | 0.46% | — | Nasm Netwide Assembler | 10/4/2026 | 17/6/2026 | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity. | |
| Analizada | Crítica (9.6) | 0.48% | — | Nasm Netwide Assembler | 10/4/2026 | 17/6/2026 | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution. | |
| Analizada | Media (5.5) | 0.36% | — | Nasm Netwide Assembler | 10/4/2026 | 17/6/2026 | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code… | |
| Aplazada | Media (5.3) | 0.29% | — | Enituretechnology LTL Freight Quotes Worldwide Express EditionAI | 7/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Andrew Lima Sitewide Notice WPAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Andrew Lima Sitewide Notice WP sitewide-notice-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sitewide Notice WP: from n/a through <= 2.4.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Bobbingwide OIKAI | 9/12/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows DOM-Based XSS.This issue affects oik: from n/a through <= 4.15.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Bobbingwide Oik-privacy-policyAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.10. | |
| Aplazada | Media (5.3) | 0.27% | — | Guihom Wide BannerAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wide Banner: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.24% | — | Bobbingwide OIKAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows Reflected XSS.This issue affects oik: from n/a through <= 4.15.2. | |
| Aplazada | Media (4.3) | 0.14% | — | Bobbingwide OIKAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide oik oik allows Cross Site Request Forgery.This issue affects oik: from n/a through <= 4.15.2. | |
| Analizada | Baja (1.9) | 0.28% | — | Nasm Netwide Assembler | 11/8/2025 | 17/6/2026 | A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.28% | — | Nasm Netwide Assembler | 11/8/2025 | 17/6/2026 | A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.26% | — | Nasm Netwide Assembler | 11/8/2025 | 17/6/2026 | A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.26% | — | Nasm Netwide Assembler | 11/8/2025 | 17/6/2026 | A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (1.9) | 0.23% | — | Nasm Netwide Assembler | 11/8/2025 | 17/6/2026 | A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (6.5) | 0.26% | — | Apwide Golive | 25/7/2025 | 5/7/2026 | Apwide Golive 10.2.0 Jira plugin allows Server-Side Request Forgery (SSRF) via the test webhook function. | |
| Aplazada | Media (5.3) | 0.34% | — | Bobbingwide OIKAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in bobbingwide oik oik allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects oik: from n/a through <= 4.15.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Sitewide Discount FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide Discount for WooCommerce: Apply Discount to All Products global-shop-discount-for-woocommerce allows Stored XSS.This issue affects Sitewide Discount for WooCommerce: Apply Discount to All Products:… | |
| Aplazada | Media (6.5) | 0.38% | — | Enituretechnology Small Package Quotes Worldwide Express EditionAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.19. | |
| Aplazada | Media (5.3) | 0.30% | — | Enituretechnology LTL Freight Quotes Worldwide Express EditionAI | 16/2/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through <= 5.0.20. | |
| Aplazada | Alta (7.1) | 0.26% | — | Enituretechnology LTL Freight Quotes Worldwide Express EditionAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition allows Reflected XSS.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through <=… | |
| Aplazada | Alta (7.1) | 0.26% | — | Optimize Worldwide Find Content IDSAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs find-content-ids allows Reflected XSS.This issue affects Find Content IDs: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Enituretechnology LTL Freight Quotes Worldwide Express EditionAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition ltl-freight-quotes-worldwide-express-edition allows SQL Injection.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through <=… | |
| Analizada | Alta (7.8) | 0.28% | — | Aertherwide Exiftags | 27/8/2024 | 17/6/2026 | Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function. |