Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.18% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption,… | |
| Analizada | Media (5.4) | 0.14% | — | Wim-leers Quick Edit | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Syarif Mobile APP EditorAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1. | |
| Analizada | Media (6.5) | 0.39% | — | Teclib-edition Glpi | 18/3/2026 | 17/6/2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue. | |
| Analizada | Alta (8.8) | 0.45% | — | Teclib-edition Glpi | 17/3/2026 | 17/6/2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue. | |
| Analizada | Crítica (9.1) | 0.30% | 💥 PoC | Teclib-edition Fields | 16/3/2026 | 17/6/2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3. | |
| Aplazada | Baja (2) | 0.33% | — | UeditAI | 16/3/2026 | 17/6/2026 | A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (4.3) | 0.14% | — | Janis Elsts Admin Menu EditorAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Site Request Forgery.This issue affects Admin Menu Editor: from n/a through <= 1.14.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Astra Bulk EditAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edit allows DOM-Based XSS.This issue affects Astra Bulk Edit: from n/a through <= 1.2.10. | |
| Aplazada | Media (6.5) | 0.22% | — | Marketing Fire Editorial CalendarAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows DOM-Based XSS.This issue affects Editorial Calendar: from n/a through <= 3.9.0. | |
| Analizada | Alta (8.8) | 0.32% | — | Teclib-edition Glpi | 11/3/2026 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation. This vulnerability… | |
| Aplazada | Alta (7.2) | 0.42% | — | Themehelper Checkout Field EditorAI | 11/3/2026 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the… | |
| Aplazada | Media (5.9) | 0.22% | — | Guest Posting Frontend Posting Front EditorAI | 11/3/2026 | 17/6/2026 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor… | |
| Aplazada | Media (6.4) | 0.16% | — | Media Library ALT Text EditorAI | 7/3/2026 | 17/6/2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.62% | 💥 PoC | Aranda Service Desk WEB EditionAI | 5/3/2026 | 17/6/2026 | An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, which is processed by… | |
| Modificada | Media (6.1) | 0.36% | — | Ckeditor5 | 5/3/2026 | 17/6/2026 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading… | |
| Aplazada | Alta (7.3) | 0.27% | — | Pdf-xchange EditorAI | 20/2/2026 | 17/6/2026 | PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of PDF-XChange Editor. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Aplazada | Alta (7.1) | 0.24% | — | Vanquish Woocommerce Bulk Product EditorAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Product Editor: from n/a through <= 3.0. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Database Software Training Consulting LTD Databank Accreditation SoftwareAI | 19/2/2026 | 25/6/2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 2026/04. | |
| Aplazada | Media (6.5) | 0.34% | — | Dell Avamar ServerAIDell Avamar Virtual EditionAI | 17/2/2026 | 17/6/2026 | Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Security. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | |
| Aplazada | Media (4.8) | 0.18% | — | Arangodb Community EditionAIArangodb AardvarkAI | 15/2/2026 | 17/6/2026 | ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Element Server Suite Community EditionAIMatrix-toolsAIElement ESS Community Helm ChartAI | 12/2/2026 | 17/6/2026 | Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network… | |
| Aplazada | Media (6.4) | 0.24% | — | Flask Micro Code EditorAI | 11/2/2026 | 17/6/2026 | The Flask Micro code-editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's codeflask shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 8.1% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 10/2/2026 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.29% | — | Sceditor | 6/2/2026 | 17/6/2026 | SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options. This… |