Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

5113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Davidlingren Media Library AssistantAI7/10/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
AplazadaMedia (6.5)0.22%—WP Media Rocket Rocket Lazy LoadAI7/10/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy Load: from n/a through 2.4.0.
AplazadaBaja (2.7)0.17%—CP Media PlayerAI7/10/20267/10/2026
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that…
Pendiente de análisisAlta (7.8)0.21%—Nvidia Model OptimizerAI6/10/20267/10/2026
NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Pendiente de análisisMedia (5.5)0.12%—Nvidia TensorrtAI6/10/20267/10/2026
NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service.
AplazadaCrítica (9.3)0.25%—Gmedia Photo GalleryAI6/10/20266/10/2026
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
AplazadaAlta (7.1)0.24%—Najeebmedia Frontend File ManagerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
AplazadaAlta (7.1)0.24%—Joomunited WP Media FolderAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions.
AplazadaMedia (5.5)0.21%—File Media RenamerAI6/10/20266/10/2026
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that…
Pendiente de análisisMedia (6.7)0.11%—Mediatek MteeAI5/10/20266/10/2026
In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607.
Pendiente de análisisMedia (6.7)0.11%—Mediatek MteeAI5/10/20266/10/2026
In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608.
Pendiente de análisisMedia (6.7)0.11%—Mediatek ApusysAI5/10/20266/10/2026
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143.
Pendiente de análisisMedia (5.3)0.18%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
Pendiente de análisisMedia (5.3)0.18%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
Pendiente de análisisMedia (6.7)0.12%—Mediatek CcciAI5/10/20266/10/2026
In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID:…
Pendiente de análisisMedia (5.3)0.20%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 /…
Pendiente de análisisMedia (5.3)0.20%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 /…
Pendiente de análisisAlta (8.4)0.13%—Mediatek APUAI5/10/20266/10/2026
In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170.
Pendiente de análisisAlta (8.4)0.13%—Mediatek NeuropilotAI5/10/20266/10/2026
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.
Pendiente de análisisAlta (8.4)0.13%—Mediatek NeuropilotAI5/10/20266/10/2026
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172.
Pendiente de análisisAlta (7.5)0.23%—Mediatek ModemAI5/10/20266/10/2026
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
AplazadaCrítica (9.1)0.53%💥 PoCFastlinemedia Beaver BuilderAI3/10/20266/10/2026
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…
AplazadaMedia (6.5)0.27%—Fastlinemedia Beaver BuilderAI3/10/20266/10/2026
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaCrítica (9.8)0.64%—Json API AuthAIPI Media Json APIAI2/10/20263/10/2026
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query…
AplazadaMedia (6.1)0.29%—Social Media Share Buttons Social Sharing IconsAI1/10/20263/10/2026
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…