Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.20% | — | Wpdeveloper EmbedpressAI | 3/10/2026 | 6/10/2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (6.5) | 0.13% | — | Wpdeveloper Essential Addons FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 6.8.4. | |
| Aplazada | Media (6.4) | 0.29% | — | Wpdeveloper Essential BlocksAI | 1/10/2026 | 3/10/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker… | |
| Aplazada | Media (6.8) | 0.24% | — | Wpdeveloper EmbedpressAI | 30/9/2026 | 30/9/2026 | The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Aplazada | Media (5.9) | 0.17% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing… | |
| Aplazada | Media (6.9) | 0.37% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access… | |
| Aplazada | Media (6) | 0.21% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in… | |
| Aplazada | Media (5.3) | 0.17% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30 | |
| Aplazada | Media (6.4) | 0.21% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building… | |
| Aplazada | Media (6.3) | 0.24% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This… | |
| Aplazada | Alta (7.7) | 0.18% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full… | |
| Aplazada | Media (6.8) | 0.24% | — | Wpdeveloper EmbedpressAI | 27/9/2026 | 28/9/2026 | The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post. | |
| Aplazada | Media (6.1) | 0.37% | — | Wpdeveloper EmbedpressAI | 18/9/2026 | 18/9/2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle JdeveloperAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle JdeveloperAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Database ServerAIOracle XML Developers KITAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML… | |
| Pendiente de análisis | Alta (8.1) | 0.38% | — | Oracle JdeveloperAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle JdeveloperAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Oracle JdeveloperAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful… | |
| Aplazada | Alta (8.2) | 0.42% | — | Oracle JdeveloperAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.… | |
| Aplazada | Media (5.3) | 0.30% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows… | |
| Aplazada | Baja (2.7) | 0.28% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly… | |
| Aplazada | Baja (2.7) | 0.32% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role. | |
| Aplazada | Crítica (9.8) | 0.30% | — | Redhat Developer ToolsAI | 2/9/2026 | 3/9/2026 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper BetterdocsAI | 1/9/2026 | 1/9/2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible… |