Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1086 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaSin puntuar——If-so Dynamic ContentAI7/10/20267/10/2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
Pendiente de análisisMedia (5.3)——Opentext Content ServerAI6/10/20266/10/2026
Cross-site Scripting (XSS) in the Forums feature of OpenText Content Management Content Server could allow a bad actor to inject malicious code into a Forums web page.
AplazadaMedia (4.3)0.15%—WDS MCP Content ManagerAI6/10/20266/10/2026
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
Pendiente de análisisMedia (6.9)0.39%—Joomlafry TF ContentAI5/10/20266/10/2026
Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of…
Pendiente de análisisMedia (6.9)0.26%—Joomlafry TF ContentAI5/10/20266/10/2026
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the…
AplazadaMedia (4.3)0.15%—Deepak Anand WP Dummy Content GeneratorAI5/10/20266/10/2026
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
AplazadaAlta (8.1)0.29%—Nelio ContentAI3/10/20266/10/2026
The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaBaja (3.1)0.12%—If-so Dynamic ContentAI1/10/20261/10/2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page.
AplazadaMedia (4.7)0.18%—IF SO Dynamic ContentAI1/10/20261/10/2026
The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link.
AplazadaMedia (6.5)0.28%—MCP Content Manager LiteAI30/9/202630/9/2026
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
AplazadaAlta (7.2)0.37%—Keywordrush Content EGGAI30/9/202630/9/2026
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
AplazadaAlta (7.1)0.18%—If-so Dynamic Content PersonalizationAI30/9/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Reflected XSS.This issue affects If-So Dynamic Content Personalization: from n/a through 1.10.1.
AplazadaMedia (6.8)0.24%—Keywordrush Content EGGAI30/9/202630/9/2026
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary…
Pendiente de análisisMedia (6.5)0.76%—Plone APP DexterityAIPlone APP ContenttypesAI22/9/202625/9/2026
plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0…
Pendiente de análisisMedia (5.5)0.25%—Adobe Content CredentialsAI22/9/202623/9/2026
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a…
Pendiente de análisisMedia (4.3)1.0%—CAI Content CredentialsAI22/9/202622/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim…
En análisisMedia (6.5)1.3%—CAI Content CredentialsAI22/9/202625/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must…
En análisisMedia (4.3)1.0%—CAI Content CredentialsAI22/9/202622/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim…
En análisisMedia (5.5)0.24%—CAI Content CredentialsAI22/9/202626/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim…
En análisisAlta (7.5)0.90%—CAI Content CredentialsAI22/9/202623/9/2026
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user…
En análisisAlta (7.5)0.65%—CAI Content CredentialsAI22/9/202622/9/2026
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
AplazadaAlta (8.8)0.57%—BM Content BuilderAI22/9/202622/9/2026
The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (6.5)0.53%—BM Content BuilderAI22/9/202622/9/2026
The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the…
AplazadaAlta (7.8)0.14%—Oracle Webcenter ContentAI15/9/202617/9/2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to…
AplazadaAlta (7.7)0.41%—Contentful MCP ServerAIContentful MCP ToolsAI15/9/202630/9/2026
Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and…
Orbitaley — Vulnerabilidades