Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/12/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
ModificadaAlta (7.5)0.30%—Pdf-xchange Editor9/12/202517/6/2026
A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)0.30%—Pdf-xchange Editor9/12/202517/6/2026
A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AnalizadaMedia (6.5)0.51%—Pdf-xchange Editor2/12/202517/6/2026
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
AplazadaMedia (4.7)0.20%—Guest Posting Frontend Posting Front EditorAI24/11/202530/9/2026
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
AplazadaAlta (8.7)0.45%—Zentao BIZAIZentao MAXAIZentao Open Source EditionAI13/11/202517/6/2026
ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerability in the login functionality. The application does not properly validate the account parameter on /zentao/user-login.html before using it in a database query. A remote…
AplazadaMedia (5.3)0.29%—Comment Edit CoreAI13/11/202517/6/2026
The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.0 via the 'ajax_get_comment' function. This makes it possible for unauthenticated attackers to extract sensitive data including user IDs, IP addresses, and email…
AplazadaAlta (8.8)0.58%—Elastic Theme EditorAI11/11/202517/6/2026
The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme function in all versions up to, and including, 0.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files…
AnalizadaMedia (5.4)0.27%—AngularCkeditor57/11/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
AplazadaMedia (4.3)0.13%—Disable Content Editor FOR Specific TemplateAI24/10/202517/6/2026
The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible for unauthenticated attackers to add or delete template…
AplazadaAlta (7.1)0.30%—Ahmad Awais WP Super EditAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad Awais WP Super Edit wp-super-edit allows Reflected XSS.This issue affects WP Super Edit: from n/a through <= 2.5.4.
AplazadaAlta (8.8)0.40%—Themeeditor Theme EditorAI18/10/202525/9/2026
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request…
AplazadaMedia (5.3)0.34%—Oceanpayment Creditcard GatewayAI15/10/202517/6/2026
The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0. This makes it possible for…
AnalizadaAlta (8.8)0.83%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.4)0.64%💥 PoCUnity Editor3/10/202517/6/2026
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code…
AplazadaMedia (4.8)0.22%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AplazadaMedia (5.9)0.38%—Managefy File Manager Code Editor AND BackupAI1/10/202517/6/2026
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and full paths to backup…
AplazadaMedia (6.5)0.21%—Wpfront User Role EditorAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor wpfront-user-role-editor allows Stored XSS.This issue affects WPFront User Role Editor: from n/a through <= 4.2.3.
AnalizadaAlta (7.5)0.37%—Dell Bsafe Micro-edition-suite25/9/202517/6/2026
Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
AplazadaBaja (1.9)0.27%—Changsha Developer Technology Iview EditorAI25/9/202517/6/2026
A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…
AnalizadaMedia (6.5)0.32%—Open-federation Json-schema-editor-visual24/9/202517/6/2026
json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of…
AplazadaMedia (6.5)0.27%—Vwthemes Ibtana Visual EditorAI22/9/202517/6/2026
Missing Authorization vulnerability in VW THEMES Ibtana ibtana-visual-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through <= 1.2.5.3.
AplazadaMedia (6.5)0.20%—Image-editor-by-pixoAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ickata Image Editor by Pixo image-editor-by-pixo allows DOM-Based XSS.This issue affects Image Editor by Pixo: from n/a through <= 2.3.8.