Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 29/9/2026 | 30/9/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Aplazada | Media (5.3) | 0.43% | — | WIXAI | 12/2/2026 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in the Wix web application, where the endpoint ' https://manage.wix.com/account/account-settings ', responsible for uploading SVG images, does not properly sanitize the content. An authenticated attacker could upload an SVG file containing embedded JavaScript code,… | |
| Analizada | Media (4.8) | 0.44% | — | WIX JAM | 21/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of the component Jinja2 Template Handler. The manipulation of the argument config['template'] leads to improper neutralization of special… | |
| Aplazada | Alta (7.9) | 0.24% | — | WIX ToolsetAI | 24/3/2024 | 17/6/2026 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user to delete protected directories. `RemoveFolderEx` deletes an entire directory tree during installation or uninstallation. It… | |
| Aplazada | Alta (7.3) | 0.46% | — | WIX ToolsetAI | 24/3/2024 | 17/6/2026 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points to an insecure directory C:\Windows\Temp to drop and load multiple binaries. Standard users can hijack the binary before it's loaded in the… | |
| Modificada | Alta (7.8) | 0.24% | — | Firegiant WIX Toolset | 7/2/2024 | 17/6/2026 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges. This impacts any installer built with the WiX installer framework. This issue has been patched in version… | |
| Modificada | Crítica (9.8) | 1.0% | — | WIX Embedded Mysql | 28/7/2023 | 17/6/2026 | wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument. | |
| Modificada | Media (6.1) | 0.89% | — | LibkiwixFedoraproject Fedora | 25/3/2022 | 17/6/2026 | libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0. | |
| Modificada | Media (5.5) | 1.5% | — | Firegiant WIX Toolset | 19/9/2019 | 17/6/2026 | An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZIP archive extraction, because the full name of an archive file (even with a ../ sequence) is concatenated with the… | |
| Modificada | Alta (8.1) | 2.2% | — | Node-wixtoolset Project Node-wixtoolset | 4/6/2018 | 17/6/2026 | wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the… | |
| Modificada | Media (4.3) | 1.9% | — | Kiwix | 21/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search. | |
| Modificada | Alta (7.1) | 1.5% | — | Choice Wireless Wixfmr-111 | 2/7/2013 | 16/6/2026 | ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information via an Ajax (1) wmxState or (2) netState request. | |
| Modificada | Alta (9.3) | 2.9% | — | Choice-wireless Wixfmr-111 | 30/6/2013 | 16/6/2026 | ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to execute arbitrary commands via shell metacharacters in the pip parameter in an Ajax tag_ipPing request, a different vulnerability than CVE-2013-3581. | |
| Modificada | Alta (7.5) | 0.92% | — | Uwix COM Digifolio | 15/9/2009 | 16/6/2026 | SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php. |