Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.44%—Mrvinoth ALL Video ShareAI28/8/202628/8/2026
Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors
AplazadaAlta (7.5)0.43%—VinoAI23/7/202623/7/2026
Contributor Local File Inclusion in Vino <= 1.9 versions.
AplazadaAlta (7.1)0.27%—M A Vinoth Kumar Category WidgetAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Category Widget category-widget allows Reflected XSS.This issue affects Category Widget: from n/a through <= 2.0.2.
AplazadaAlta (7.1)0.26%—Intel Openvino Model ServerAI13/5/202517/6/2026
Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (5.3)0.33%—Vinodvaswani9 Bulk Assign Linked Products FOR WoocommerceAI24/4/202517/6/2026
Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1.
AplazadaMedia (6)0.30%—Intel Distribution OF Openvino Model ServerAI13/11/202417/6/2026
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (6.5)0.31%—Vinod Dalvi Login Logout Register MenuAI3/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vinod Dalvi Login Logout Register Menu allows Stored XSS.This issue affects Login Logout Register Menu: from n/a through 2.0.
ModificadaAlta (7.5)0.63%—Intel Openvino Model Server14/11/202317/6/2026
Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaMedia (5.5)0.18%—Intel Openvino14/11/202317/6/2026
Protection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.16%—Intel Openvino11/8/202317/6/2026
Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.60%—Intel Openvino11/11/202217/6/2026
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.
ModificadaMedia (5.5)0.22%—Intel Distribution OF Openvino Toolkit17/11/202117/6/2026
Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.28%—Intel Distribution OF Openvino Toolkit13/8/202017/6/2026
Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)1.8%—Vino Project Vino9/10/201917/6/2026
tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.
ModificadaBaja (3.9)0.44%—Intel Openvino18/2/201917/6/2026
Logic error in the installer for Intel(R) OpenVINO(TM) 2018 R3 and before for Linux may allow a privileged user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.32%—Intel Openvino Toolkit12/9/201817/6/2026
Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access.
ModificadaAlta (7.5)2.2%—Vinojcardoza Ajax Post Search8/1/201516/6/2026
SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.
ModificadaAlta (7.1)8.7%—David King VinoCanonical Ubuntu Linux1/10/201316/6/2026
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service…
ModificadaMedia (5.1)2.3%—David King Vino12/3/201316/6/2026
Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easier for remote attackers to perform further attacks.
ModificadaMedia (4.6)1.6%—David King Vino12/3/201316/6/2026
Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which might make it easier for remote attackers to perform attacks.
ModificadaMedia (5)2.4%—David King Vino1/10/201216/6/2026
Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
ModificadaMedia (5)1.5%—Jason Savino FP28/8/201216/6/2026
The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers to modify access permissions via unspecified vectors.
ModificadaBaja (3.5)1.5%—David King Vino10/5/201116/6/2026
The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a…
ModificadaBaja (3.5)2.3%—David King Vino10/5/201116/6/2026
The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2)…