Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.11% | — | Mediatek Mt6768 FirmwareMediatek Mt6789 FirmwareMediatek Mt6877 FirmwareMediatek Mt6899 Firmware+13 | 4/5/2026 | 17/6/2026 | In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296. | |
| Aplazada | Baja (2.1) | 0.42% | — | AV Stumpfl Pixera TWO Media ServerAI | 3/5/2026 | 17/6/2026 | A vulnerability has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. The affected element is an unknown function of the component Service Port 1338. Such manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 25.2 R3 is sufficient to fix… | |
| Aplazada | Media (6.5) | 0.34% | — | Najeebmedia Frontend File ManagerAI | 3/5/2026 | 17/6/2026 | During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user… | |
| Aplazada | Media (6.9) | 0.40% | — | Klik SocialmediawebsiteAI | 25/4/2026 | 17/6/2026 | A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely. | |
| Aplazada | Media (5.1) | 0.29% | — | Semantic-mediawiki Semantic MediawikiAI | 21/4/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal… | |
| Analizada | Alta (8.1) | 0.40% | — | Sysadminsmedia Homebox | 17/4/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and… | |
| Aplazada | Alta (8.5) | 0.36% | — | Fastlinemedia Beaver BuilderAI | 15/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Blind SQL Injection.This issue affects Beaver Builder: from n/a through <= 2.10.1.2. | |
| Aplazada | Media (6.4) | 0.26% | — | Fastlinemedia Beaver BuilderAI | 8/4/2026 | 24/7/2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[js]' parameter in versions up to, and including, 2.10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.22% | — | Mediaron Custom Query BlocksAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia Score ExtensionAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia CampaigneventsAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch. | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Wikimedia Mediawiki Centralauth ExtensionAI | 7/4/2026 | 21/7/2026 | Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | |
| Pendiente de análisis | Media (6.9) | 0.43% | — | Wikimedia Mediawiki Growthexperiments ExtensionAI | 7/4/2026 | 21/7/2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue was remediated only on the `master` branch. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia GlobalwatchlistAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44,… | |
| Analizada | Media (6.3) | 0.24% | — | Mediawiki Cargo | 7/4/2026 | 24/7/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7. | |
| Analizada | Media (5.1) | 0.24% | — | Mediawiki Cargo | 7/4/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extension: before 3.8.7. | |
| Analizada | Media (6.3) | 0.30% | — | Mediawiki Cargo | 7/4/2026 | 24/7/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia Proofreadpage ExtensionAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - ProofreadPage Extension allows XSS Targeting Non-Script Elements. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44,… | |
| Analizada | Media (6.3) | 0.24% | — | Mediawiki Cargo | 7/4/2026 | 24/7/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7. | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Wikimedia MediawikiAIWikimedia ReportincidentAI | 7/4/2026 | 21/7/2026 | Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch. | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | Wikimedia MediawikiAIWikimedia WikiloveAI | 7/4/2026 | 21/7/2026 | Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | |
| Aplazada | Alta (7.5) | 0.16% | — | Analytify Simple Social Media Share ButtonsAI | 7/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0. | |
| Analizada | Media (4.3) | 0.19% | — | Mediatek Mt6813 Firmware | 7/4/2026 | 17/6/2026 | In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899. | |
| Analizada | Alta (8.8) | 0.34% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 FirmwareMediatek Mt6833 Firmware+58 | 7/4/2026 | 17/6/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Analizada | Alta (8) | 0.29% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6779 FirmwareMediatek Mt6781 Firmware+54 | 7/4/2026 | 24/7/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… |