Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.27% | — | Zipperapp MY Teditor | 5/2/2026 | 5/7/2026 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | |
| Analizada | Media (5.4) | 0.23% | — | Foxit PDF Editor Cloud | 3/2/2026 | 17/6/2026 | Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution when the layer is referenced. This issue affects pdfonline.foxit.com: before 2026‑02‑03. | |
| Analizada | Media (5.4) | 0.23% | — | Foxit PDF Editor Cloud | 3/2/2026 | 17/6/2026 | Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.foxit.com: before… | |
| Analizada | Ninguna (0) | 0.18% | — | Mediawiki Visual Editor | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated with program files src/ce/ve.Ce.ClipboardHandler.Js. This issue affects VisualEditor: from * before 1.39.14, 1.43.4, 1.44.1. | |
| Analizada | Ninguna (0) | 0.17% | — | Mediawiki Visual Editor | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated with program files includes/ApiVisualEditorEdit.Php, modules/ve-mw/init/targets/ve.Init.Mw.DesktopArticleTarget.Js,… | |
| Aplazada | Ninguna (0) | 0.40% | — | Wikimedia ConfirmeditAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation ConfirmEdit. This vulnerability is associated with program files includes/FancyCaptcha/ApiFancyCaptchaReload.Php. This issue affects ConfirmEdit: *. | |
| Analizada | Media (5.3) | 0.27% | — | Cksource Ckeditor 5 Premium Features | 28/1/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4. | |
| Aplazada | Media (4.3) | 0.18% | — | Login Page EditorAI | 24/1/2026 | 17/6/2026 | The Login Page Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the devotion_loginform_process() AJAX action. This makes it possible for unauthenticated attackers to update the plugin's login page settings via… | |
| Aplazada | Alta (8.5) | 0.14% | — | PDF Complete Corporate EditionAI | 23/1/2026 | 17/6/2026 | PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated… | |
| Aplazada | Alta (8.8) | 0.40% | — | Melapress Role EditorAI | 23/1/2026 | 17/6/2026 | The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Baja (1.3) | 0.40% | — | Neo4j Enterprise EditionAI | 22/1/2026 | 17/6/2026 | Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. The vulnerability allows attacker without read access to a property to infer information about its value by trying to enumerate all… | |
| Aplazada | Media (5.1) | 0.45% | — | MoeditorAI | 16/1/2026 | 17/6/2026 | Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload specially crafted markdown files with embedded JavaScript that execute when opened, potentially enabling remote code execution on the victim's system. | |
| Aplazada | Alta (8.5) | 0.15% | — | Emerson PAC Machine EditionAI | 13/1/2026 | 17/6/2026 | Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem… | |
| Modificada | Media (5.3) | 0.83% | — | Phphtmledit Rich Text Editor | 13/1/2026 | 17/6/2026 | CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal… | |
| Aplazada | Media (4.4) | 0.18% | — | Simple User Meta EditorAI | 7/1/2026 | 7/10/2026 | The Simple User Meta Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user meta value field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Alta (7.1) | 0.18% | — | Christopher Churchill Custom-post-editAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christopher Churchill custom-post-edit front-end-post-edit allows Reflected XSS.This issue affects custom-post-edit: from n/a through <= 1.0.4. | |
| Aplazada | Baja (2) | 0.22% | — | Cloudpanel Community EditionAI | 30/12/2025 | 7/10/2026 | A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (5.4) | 0.16% | — | Marketing Fire Editorial CalendarAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editorial Calendar: from n/a through <= 3.8.8. | |
| Aplazada | Crítica (9.3) | 0.65% | — | Xinha Wysiwyg EditorAI | 19/12/2025 | 17/6/2026 | InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset… | |
| Analizada | Media (5.4) | 0.18% | — | Foxit PDF Editor Cloud | 19/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, embedded HTML or… | |
| Analizada | Media (5.4) | 0.11% | — | Foxit PDF Editor Cloud | 19/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name, which is later rendered into the DOM without proper sanitization. As a result, the injected script executes each time the Trusted… | |
| Analizada | Media (5.4) | 0.18% | — | Foxit PDF Editor Cloud | 19/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sanitized or validated before being inserted into the HTML structure. As a result, embedded HTML or JavaScript within a crafted SVG may execute… | |
| Analizada | Media (5.4) | 0.18% | — | Foxit PDF Editor Cloud | 19/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored via the Identity “First Name” field, which is later rendered into the DOM without proper sanitization. As a result, the injected script may… | |
| Analizada | Media (5.4) | 0.21% | — | Foxit PDF Editor Cloud | 19/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to execute arbitrary JavaScript when a crafted postMessage is received. | |
| Analizada | Alta (7.8) | 0.30% | — | Foxit PDF EditorFoxit PDF Reader | 19/12/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code. |