Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.88% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In… | |
| Pendiente de análisis | Alta (7.1) | 0.58% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately… | |
| Pendiente de análisis | Alta (7.1) | 0.64% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then… | |
| Pendiente de análisis | Alta (7.6) | 0.42% | — | Aomedia LibaomAI | 19/6/2026 | 6/10/2026 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds… | |
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 18/6/2026 | 18/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35. | |
| Aplazada | Alta (7.5) | 0.50% | — | Joomunited WP Media FolderAI | 17/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. | |
| Aplazada | Media (4.3) | 0.21% | — | Inisev Social Media AND Share IconsAI | 17/6/2026 | 1/10/2026 | : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Media Library AssistantAI | 16/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Rtcamp RtmediaAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. | |
| Aplazada | Media (6.5) | 0.36% | — | Hedef Media Promotion Interactive Media Marketing INC Related Marketing CloudAI | 12/6/2026 | 17/6/2026 | Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026. | |
| Aplazada | Media (6.4) | 0.32% | — | Shortpixel Enable Media ReplaceAI | 9/6/2026 | 23/7/2026 | The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Analizada | Alta (7.8) | 0.12% | — | Synology Active Backup FOR Business Recovery Media Creator | 3/6/2026 | 22/7/2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |
| Analizada | Media (5.5) | 0.10% | — | Mediatek Mt7902 FirmwareMediatek Mt7920 FirmwareMediatek Mt7921 FirmwareMediatek Mt7922 Firmware+2 | 1/6/2026 | 22/7/2026 | In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338. | |
| Analizada | Alta (7.8) | 0.11% | — | Mediatek Mt6739 FirmwareMediatek Mt6761 FirmwareMediatek Mt6765 FirmwareMediatek Mt6768 Firmware+32 | 1/6/2026 | 22/7/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784. | |
| Analizada | Media (6.4) | 0.08% | — | Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+32 | 1/6/2026 | 22/7/2026 | In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786. | |
| Analizada | Media (6.7) | 0.11% | — | Mediatek Mt8673 FirmwareMediatek Mt8765 FirmwareMediatek Mt8766 FirmwareMediatek Mt8768 Firmware+32 | 1/6/2026 | 22/7/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. | |
| Analizada | Alta (8) | 0.43% | 💥 PoC | Mediatek Mt6890 FirmwareMediatek Mt7615 FirmwareMediatek Mt7915 FirmwareMediatek Mt7916 Firmware+5 | 1/6/2026 | 22/7/2026 | In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295. | |
| Aplazada | Alta (8.7) | 0.75% | — | Spatie Laravel Media LibraryAI | 29/5/2026 | 22/7/2026 | Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .php stems in saved… | |
| Aplazada | Media (5.3) | 0.42% | — | Spatie Laravel Media LibraryAI | 29/5/2026 | 22/7/2026 | Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php. | |
| Aplazada | Alta (8.1) | 0.32% | — | Media Library AssistantAI | 29/5/2026 | 21/7/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into… | |
| Aplazada | Media (4.3) | 0.27% | — | Wp-media AdminimizeAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11. | |
| Modificada | Alta (7.8) | 0.22% | — | Mediaarea Mediainfolib | 26/5/2026 | 23/9/2026 | A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted media file that contains ID3v2 tags can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.24% | — | Mediaarea Mediainfolib | 26/5/2026 | 23/9/2026 | A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted .lxf file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Aplazada | Media (5.5) | 0.52% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.50% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. |