Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
1900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.23% | — | Alex4ssb ADB Explorer | 25/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the ADB binary to be executed, to be set to a Universal Naming Convention (UNC) path in the application's settings file. This allows an attacker… | |
| Analizada | Alta (7.1) | 0.23% | — | Alex4ssb ADB Explorer | 20/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a custom data directory, but only check… | |
| Aplazada | Alta (7.8) | 0.20% | — | Alex4ssb ADB ExplorerAI | 20/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authenticity of the ADB binary path specified in the ManualAdbPath setting before executing it, allowing arbitrary code execution with the privileges of the current user. An attacker can exploit this by… | |
| Aplazada | Alta (7.8) | 0.67% | — | Newtonsoft JsonAIAlex4ssb ADB ExplorerAI | 13/2/2026 | 17/6/2026 | ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to… | |
| Analizada | Media (6.7) | 0.20% | — | Nsasoft Product KEY Explorer | 12/2/2026 | 17/6/2026 | Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow when pasted into the registration name… | |
| Modificada | Media (6.5) | 0.54% | — | Microsoft Azure IOT Explorer | 10/2/2026 | 17/6/2026 | Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.4) | 0.38% | — | 10-strike Network Inventory ExplorerAI | 5/2/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code… | |
| Aplazada | Alta (8.4) | 0.71% | — | 10-strike Network Inventory ExplorerAI | 5/2/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution… | |
| Analizada | Media (6.7) | 0.27% | — | Nsasoft Product KEY Explorer | 5/2/2026 | 29/6/2026 | Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the… | |
| Aplazada | Media (4.9) | 0.47% | — | Bowo Code ExplorerAI | 4/2/2026 | 17/6/2026 | The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via the 'file' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Alta (8.4) | 0.54% | — | 10-strike Network Inventory ExplorerAI | 28/1/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code execution. | |
| Analizada | Alta (7.4) | 0.60% | — | Microsoft Azure Data Explorer | 22/1/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.5) | 0.15% | — | Fspro Event LOG ExplorerAI | 21/1/2026 | 17/6/2026 | Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations that will be executed with… | |
| Aplazada | Media (5.1) | 0.36% | — | Markdown ExplorerAI | 16/1/2026 | 17/6/2026 | Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads that execute in the application's privileged renderer context, allowing code execution on… | |
| Analizada | Alta (8.4) | 0.71% | — | 10-strike Network Inventory Explorer | 15/1/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the target system. | |
| Analizada | Alta (8.5) | 0.24% | — | 10-strike Network Inventory Explorer | 15/1/2026 | 17/6/2026 | 10-Strike Network Inventory Explorer Pro 9.31 contains an unquoted service path vulnerability in the srvInventoryWebServer service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path segments to achieve privilege escalation and execute code… | |
| Analizada | Alta (7) | 0.58% | — | Explorerplusplus Explorer++ | 13/1/2026 | 17/6/2026 | Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious… | |
| Analizada | Media (5.3) | 0.32% | — | Kodcloud Kodexplorer | 11/12/2025 | 17/6/2026 | KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication. | |
| Analizada | Media (5.5) | 0.38% | — | Ml-explore MLX | 21/11/2025 | 17/6/2026 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched… | |
| Analizada | Media (5.5) | 0.53% | — | Ml-explore MLX | 21/11/2025 | 17/6/2026 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue has been patched in… | |
| Aplazada | Alta (8.2) | 0.16% | — | Apollo SandboxAISpeed Software ExplorerAI | 26/9/2025 | 17/6/2026 | Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the… | |
| Aplazada | Media (6.9) | 0.13% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service allows a denial-of-service attack, leaving… | |
| Aplazada | Alta (8.6) | 0.15% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an… | |
| Aplazada | Alta (8.6) | 0.20% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an… | |
| Aplazada | Alta (7.2) | 0.31% | — | Cognex In-sight ExplorerAICognex In-sight Camera FirmwareAI | 18/9/2025 | 17/6/2026 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSerialPort functionality to modify relevant device… |