Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2777 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | CP Media PlayerAI | 7/10/2026 | 7/10/2026 | The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Gmedia Photo GalleryAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Najeebmedia Frontend File ManagerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Joomunited WP Media FolderAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions. | |
| Aplazada | Media (5.5) | 0.13% | — | File Media RenamerAI | 6/10/2026 | 6/10/2026 | The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that… | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | Mediatek MteeAI | 5/10/2026 | 6/10/2026 | In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607. | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | Mediatek MteeAI | 5/10/2026 | 6/10/2026 | In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608. | |
| Pendiente de análisis | Media (6.7) | 0.11% | — | Mediatek ApusysAI | 5/10/2026 | 6/10/2026 | In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143. | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Mediatek ModemAI | 5/10/2026 | 6/10/2026 | In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Mediatek ModemAI | 5/10/2026 | 6/10/2026 | In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Pendiente de análisis | Media (6.7) | 0.12% | — | Mediatek CcciAI | 5/10/2026 | 6/10/2026 | In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, memory corruption, crashes, or privilege escalation if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID:… | |
| Pendiente de análisis | Media (5.3) | 0.20% | — | Mediatek ModemAI | 5/10/2026 | 6/10/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 /… | |
| Pendiente de análisis | Media (5.3) | 0.20% | — | Mediatek ModemAI | 5/10/2026 | 6/10/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 /… | |
| Pendiente de análisis | Alta (8.4) | 0.13% | — | Mediatek APUAI | 5/10/2026 | 6/10/2026 | In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: MSV-9170. | |
| Pendiente de análisis | Alta (8.4) | 0.13% | — | Mediatek NeuropilotAI | 5/10/2026 | 6/10/2026 | In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171. | |
| Pendiente de análisis | Alta (8.4) | 0.13% | — | Mediatek NeuropilotAI | 5/10/2026 | 6/10/2026 | In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172. | |
| Pendiente de análisis | Alta (7.5) | 0.23% | — | Mediatek ModemAI | 5/10/2026 | 6/10/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Aplazada | Crítica (9.1) | 0.53% | 💥 PoC | Fastlinemedia Beaver BuilderAI | 3/10/2026 | 6/10/2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Aplazada | Media (6.5) | 0.27% | — | Fastlinemedia Beaver BuilderAI | 3/10/2026 | 6/10/2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Json API AuthAIPI Media Json APIAI | 2/10/2026 | 3/10/2026 | The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query… | |
| Aplazada | Media (6.1) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 1/10/2026 | 3/10/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Pendiente de análisis | Baja (1.2) | 0.30% | 💥 PoC | Wikimedia MediasearchAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Baja (1.1) | 0.29% | 💥 PoC | Wikimedia CommonsmetadataAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Alta (7.4) | 0.33% | 💥 PoC | Wikimedia WikilambdaAI | 30/9/2026 | 6/10/2026 | Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46. | |
| Pendiente de análisis | Baja (1.2) | 0.30% | 💥 PoC | Wikimedia Page FormsAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. |