Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.39%—KDE KIOAI1/9/20261/9/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.
AplazadaMedia (5.5)0.61%—Dekdee Adobe-xd-mcpAI25/8/202626/8/2026
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely.…
AplazadaMedia (5.3)0.37%—Aerostackdev Aerostack-mcpAI9/7/20263/9/2026
A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument media_url leads to server-side request forgery. The attack may be launched…
Pendiente de análisisAlta (7)0.16%—KDE PlasmaAIFreedesktop DbusAI13/5/202617/6/2026
The new upstream added a privileged D-Bus helper called plasmaloginauthhelper, which suffers from multiple issues, e.g.aA compromised plasmalogin service account can chown() arbitrary files in the system.
AplazadaMedia (6.5)0.16%—KdenliveAI9/5/202620/7/2026
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
AnalizadaAlta (7.8)0.25%—KDE Kcoreaddons28/4/202617/6/2026
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input…
Pendiente de análisisMedia (6.5)0.16%—KDE DolphinAI28/4/202617/6/2026
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. (By default,…
AplazadaMedia (4)0.17%—KDE AriannaAI24/4/202617/6/2026
bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.
Pendiente de análisisMedia (6.9)0.16%—KDE KleopatraAI21/4/202617/6/2026
KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.
ModificadaMedia (4.3)0.56%—Ritwickdey Live Server16/2/202617/6/2026
An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.
AplazadaBaja (3.4)0.22%—KDE MessagelibAI1/1/202617/6/2026
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
AplazadaMedia (4.7)0.20%—KDE ConnectAIKDE Connect IOSAIKDE Connect AndroidAIGnome GsconnectAI+15/12/202517/6/2026
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
AplazadaMedia (4.3)0.12%—KDE ConnectAIKDE Connect AndroidAIKDE Connect IOSAIGnome GsconnectAI+15/12/202517/6/2026
In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before…
AplazadaMedia (4.3)0.18%—KDE ConnectAI5/12/202517/6/2026
In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.
AplazadaMedia (4.3)0.18%—KDE ConnectAI5/12/202517/6/2026
In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.
AplazadaMedia (4.7)0.15%—KDE ConnectAIValentAIGsconnectAI5/12/202525/9/2026
The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
AplazadaMedia (6.7)0.21%—KDE KritaAI26/11/202517/6/2026
In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even when a number of pixels becomes negative.
AplazadaBaja (3.2)0.14%—KDE SkanpageAI26/11/202517/6/2026
In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.
AplazadaMedia (5.3)0.14%—Lightdm-kde-greeterAI12/11/202517/6/2026
A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.
AplazadaMedia (6.5)0.21%—Akdevs Genealogical-treeAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in akdevs Genealogical Tree genealogical-tree allows Stored XSS.This issue affects Genealogical Tree: from n/a through <= 2.2.7.
AplazadaMedia (6.4)0.24%—Flickdevs Countdown Timer FOR ElementorAI11/9/202517/6/2026
The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_label' Parameter in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaAlta (8.8)0.75%—JkdevkitAI3/7/202517/6/2026
The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' function in all versions up to, and including, 1.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on…
AplazadaAlta (7)0.47%—LibblockdevAIFreedesktop UdisksAI19/6/202530/6/2026
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able…
AplazadaAlta (8.2)0.67%—KDE KonsoleAI11/6/202517/6/2026
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that…
AnalizadaMedia (6.5)0.30%—Flickdevs Countdown Timer FOR Wordpress Block Editor15/5/202517/6/2026
The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.