Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.24% | — | Autodesk ArnoldAIAutodesk 3DS MAXAI | 4/2/2026 | 17/6/2026 | A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Analizada | Media (5.4) | 0.27% | — | Arnoldgoodway Tweaker5 | 13/9/2024 | 17/6/2026 | The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Media (5.4) | 0.27% | — | Arnoldgoodway Neighborly | 13/9/2024 | 17/6/2026 | The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Media (5) | 2.0% | — | Jeremy Arnold Worm Webserver | 20/10/2000 | 16/6/2026 | Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.6% | — | Jeremy Arnold Worm Webserver | 20/10/2000 | 16/6/2026 | Worm HTTP server allows remote attackers to cause a denial of service via a long URL. |