Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.41% | — | Jose Mortellaro Content NO CacheAI | 27/6/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.This issue affects Content No Cache: from n/a through <= 0.1.4. | |
| Analizada | Crítica (9.8) | 0.70% | — | Beakon Learning Management System Sharable Content Object Reference Model | 23/6/2025 | 17/6/2026 | SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file | |
| Aplazada | Media (5.3) | 0.29% | — | ContentstudioAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contentstudio: from n/a through <= 1.3.7. | |
| Aplazada | Media (6.5) | 0.19% | — | If-so Dynamic Content PersonalizationAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.3.1. | |
| Aplazada | Media (6.5) | 0.40% | — | Deepak Anand WP Dummy Content GeneratorAI | 17/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through <= 3.4.6. | |
| Aplazada | Media (5.9) | 0.26% | — | Iwebix WP Featured Content SliderAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IWEBIX WP Featured Content Slider wp-featured-content-slider allows Stored XSS.This issue affects WP Featured Content Slider: from n/a through <= 2.6. | |
| Aplazada | Media (6.4) | 0.22% | — | BM Content BuilderAI | 6/6/2025 | 17/6/2026 | The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Analizada | Media (5.3) | 0.48% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/users.php. The manipulation of the argument delete leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.48% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/users.php. The manipulation of the argument change_to_admin leads to sql injection. The attack can be… | |
| Analizada | Media (6.9) | 0.58% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been classified as critical. Affected is an unknown function of the file /publicposts.php. The manipulation of the argument post leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.1) | 0.37% | 💥 PoC | Motivian Content Management System | 4/6/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components. | |
| Analizada | Alta (8.2) | 0.59% | 💥 PoC | Motivian Content Management System | 4/6/2025 | 17/6/2026 | File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component. | |
| Analizada | Baja (3.1) | 0.22% | — | Single Content Sync Project Single Content Sync | 21/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12. | |
| Analizada | Media (6.1) | 0.26% | — | IBM Content Navigator | 16/5/2025 | 17/6/2026 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (4.8) | 0.30% | — | Wp-buy WP Content Copy Protection & NO Right Click | 15/5/2025 | 17/6/2026 | The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.52% | 💥 Exploit | Wp-buy WP Content Copy Protection & NO Right Click | 15/5/2025 | 17/6/2026 | The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites | |
| Analizada | Media (5.4) | 0.30% | — | If-so Dynamic Content Personalization | 15/5/2025 | 17/6/2026 | The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Alta (7.2) | 0.36% | — | WP Content Security PluginAI | 15/5/2025 | 17/6/2026 | The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and effective-directive parameters in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.24% | — | ContentstudioAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contentstudio: from n/a through <= 1.3.5. | |
| Aplazada | Media (6.5) | 0.26% | — | Code-atlantic Content ControlAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Content Control content-control allows DOM-Based XSS.This issue affects Content Control: from n/a through <= 2.6.1. | |
| Aplazada | Media (4.3) | 0.17% | — | Senols Gpt3-ai-content-generatorAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in senols GPT3 AI Content Writer gpt3-ai-content-generator allows Cross Site Request Forgery.This issue affects GPT3 AI Content Writer: from n/a through <= 1.9.14. | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /admin/update_main_topic_img.php?topic_id=529. The manipulation of the argument stopic_id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.1) | 0.37% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation of the argument Cover Image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… |