Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.31% | — | Mediatek Mt6813 FirmwareMediatek Mt6815 FirmwareMediatek Mt6835 FirmwareMediatek Mt6878 Firmware+15 | 7/4/2026 | 24/7/2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID:… | |
| Analizada | Alta (7.5) | 0.52% | — | Zlmediakit | 6/4/2026 | 24/7/2026 | ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A crafted VP9 RTP packet with a 1-byte payload (0xFF, all flags set) causes… | |
| Aplazada | Media (6.5) | 0.22% | — | Davidlingren Media Library AssistantAI | 6/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34. | |
| Aplazada | Alta (8.5) | 1.2% | 💥 Exploit | Davidlingren Media Library AssistantAI | 6/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34. | |
| Aplazada | Baja (2) | 0.33% | — | Welovemedia FfmateAI | 1/4/2026 | 17/6/2026 | A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component Webhook Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Plank Laravel-mediableAI | 26/3/2026 | 10/8/2026 | plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign… | |
| Aplazada | Alta (7.7) | 0.33% | — | Designingmedia EnergoxAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.2. | |
| Aplazada | Alta (7.7) | 0.33% | — | Designingmedia Instant VAAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.18% | — | Softwebmedia Gyan ElementsAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softwebmedia Gyan Elements gyan-elements allows Reflected XSS.This issue affects Gyan Elements: from n/a through <= 2.2.1. | |
| Analizada | Media (5.3) | 0.29% | — | Imagexmedia Material Icons | 25/3/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4. | |
| Aplazada | Alta (8.8) | 0.27% | — | Netartmedia Vlog SystemAI | 24/3/2026 | 17/6/2026 | Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with malicious email values in the forgotten_password module to extract sensitive… | |
| Analizada | Media (6.9) | 0.18% | — | Ventismedia Mediamonkey | 21/3/2026 | 7/10/2026 | MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the… | |
| Analizada | Baja (2.7) | 0.32% | — | Qnap Media Streaming Add-on | 20/3/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later | |
| Aplazada | Media (4.3) | 0.19% | — | ADD Custom Fields TO MediaAI | 19/3/2026 | 17/6/2026 | The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add field' operation… | |
| Aplazada | Media (5.9) | 0.24% | — | Wp-media WP RocketAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket allows Stored XSS.This issue affects WP Rocket: from n/a through 3.19.4. | |
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.32. | |
| Analizada | Alta (8.8) | 0.46% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass authentication,… | |
| Analizada | Alta (8.8) | 0.46% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_email parameter. Attackers can send POST requests to index.php with malicious payloads in the user_email field to bypass authentication,… | |
| Analizada | Alta (8.8) | 0.37% | — | Netartmedia PHP Mall | 12/3/2026 | 17/6/2026 | Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract… | |
| Analizada | Alta (8.8) | 0.36% | — | Netartmedia PHP Mall | 12/3/2026 | 17/6/2026 | Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various parameters. Attackers can craft malicious requests with SQL payloads to extract sensitive database information including user credentials… | |
| Aplazada | Alta (8.8) | 0.25% | — | Netartmedia Event PortalAI | 12/3/2026 | 17/6/2026 | Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL payloads in the Email field to extract… | |
| Analizada | Alta (8.8) | 0.32% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to… | |
| Aplazada | Alta (8.8) | 0.25% | — | Netartmedia PHP Dating SiteAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive… | |
| Aplazada | Alta (8.8) | 0.25% | — | Netartmedia PHP CAR DealerAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in the features[] parameter to extract… | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia PHP Business DirectoryAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract… |