Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.44% | — | Mrvinoth ALL Video ShareAI | 28/8/2026 | 28/8/2026 | Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors | |
| Aplazada | Alta (7.5) | 0.43% | — | VinoAI | 23/7/2026 | 23/7/2026 | Contributor Local File Inclusion in Vino <= 1.9 versions. | |
| Aplazada | Alta (7.1) | 0.27% | — | M A Vinoth Kumar Category WidgetAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Category Widget category-widget allows Reflected XSS.This issue affects Category Widget: from n/a through <= 2.0.2. | |
| Aplazada | Alta (7.1) | 0.26% | — | Intel Openvino Model ServerAI | 13/5/2025 | 17/6/2026 | Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (5.3) | 0.33% | — | Vinodvaswani9 Bulk Assign Linked Products FOR WoocommerceAI | 24/4/2025 | 17/6/2026 | Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1. | |
| Aplazada | Media (6) | 0.30% | — | Intel Distribution OF Openvino Model ServerAI | 13/11/2024 | 17/6/2026 | Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (6.5) | 0.31% | — | Vinod Dalvi Login Logout Register MenuAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vinod Dalvi Login Logout Register Menu allows Stored XSS.This issue affects Login Logout Register Menu: from n/a through 2.0. | |
| Modificada | Alta (7.5) | 0.63% | — | Intel Openvino Model Server | 14/11/2023 | 17/6/2026 | Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Openvino | 14/11/2023 | 17/6/2026 | Protection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel Openvino | 11/8/2023 | 17/6/2026 | Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.60% | — | Intel Openvino | 11/11/2022 | 17/6/2026 | Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Distribution OF Openvino Toolkit | 17/11/2021 | 17/6/2026 | Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Distribution OF Openvino Toolkit | 13/8/2020 | 17/6/2026 | Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 1.8% | — | Vino Project Vino | 9/10/2019 | 17/6/2026 | tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL. | |
| Modificada | Baja (3.9) | 0.44% | — | Intel Openvino | 18/2/2019 | 17/6/2026 | Logic error in the installer for Intel(R) OpenVINO(TM) 2018 R3 and before for Linux may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Openvino Toolkit | 12/9/2018 | 17/6/2026 | Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access. | |
| Modificada | Alta (7.5) | 2.2% | — | Vinojcardoza Ajax Post Search | 8/1/2015 | 16/6/2026 | SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.1) | 8.7% | — | David King VinoCanonical Ubuntu Linux | 1/10/2013 | 16/6/2026 | The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service… | |
| Modificada | Media (5.1) | 2.3% | — | David King Vino | 12/3/2013 | 16/6/2026 | Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks. | |
| Modificada | Media (4.6) | 1.6% | — | David King Vino | 12/3/2013 | 16/6/2026 | Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which might make it easier for remote attackers to perform attacks. | |
| Modificada | Media (5) | 2.4% | — | David King Vino | 1/10/2012 | 16/6/2026 | Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900. | |
| Modificada | Media (5) | 1.5% | — | Jason Savino FP | 28/8/2012 | 16/6/2026 | The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers to modify access permissions via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.5% | — | David King Vino | 10/5/2011 | 16/6/2026 | The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a… | |
| Modificada | Baja (3.5) | 2.3% | — | David King Vino | 10/5/2011 | 16/6/2026 | The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2)… |