Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.32% | — | Netartmedia Jobs PortalAI | 12/3/2026 | 17/6/2026 | Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email field to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia Deals PortalAI | 12/3/2026 | 17/6/2026 | Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to manipulate database queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive information or bypass authentication mechanisms. | |
| Analizada | Media (6.5) | 0.34% | — | Maykinmedia Open Forms | 11/3/2026 | 17/6/2026 | Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instructions or a deep-link to start the cosign flow. The submission reference is communicated so that the user can retrieve the submission to be cosigned. Attackers can guess a… | |
| Aplazada | Baja (2) | 0.51% | — | Mediawiki RenderblockingAI | 10/3/2026 | 17/6/2026 | RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScript. Prior to 0.1.1, there is Stored XSS in renderblocking-css with Inline Assets mode. $wgRenderBlockingInlineAssets = true and editsitecss user rights are required. This vulnerability is fixed in… | |
| Aplazada | Alta (8.8) | 0.54% | — | Mediawiki BucketAI | 10/3/2026 | 17/6/2026 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This vulnerability is fixed in 2.1.1. | |
| Aplazada | Baja (2.1) | 0.41% | — | Welovemedia FfmateAI | 8/3/2026 | 17/6/2026 | A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. This vulnerability affects the function Execute of the file /internal/service/ffmpeg/ffmpeg.go. The manipulation leads to argument injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The… | |
| Aplazada | Baja (2.1) | 0.39% | — | Welovemedia FfmateAI | 7/3/2026 | 17/6/2026 | A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /internal/service/webhook/webhook.go. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The exploit has been made available to the public and could… | |
| Aplazada | Media (4.4) | 0.20% | — | Lotekmedia Popup FormAI | 7/3/2026 | 17/6/2026 | The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (6.4) | 0.16% | — | Media Library ALT Text EditorAI | 7/3/2026 | 17/6/2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.20% | — | DA Media GiglistAI | 7/3/2026 | 17/6/2026 | The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.24% | — | Rmedia SMSAI | 6/3/2026 | 17/6/2026 | Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and… | |
| Aplazada | Media (4.3) | 0.35% | — | Media Library AssistantAI | 5/3/2026 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (6.5) | 0.33% | — | Blend Media Wordpress CTAAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through <= 2.1.2. | |
| Aplazada | Media (5.4) | 0.40% | — | Shortpixel Enable Media ReplaceAI | 4/3/2026 | 17/6/2026 | The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and… | |
| Analizada | Alta (7.4) | 0.40% | — | Sysadminsmedia Homebox | 3/3/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-For header, and 3. r.RemoteAddr (TCP connection address). These… | |
| Analizada | Media (4.3) | 0.28% | — | Sysadminsmedia Homebox | 3/3/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although the application does… | |
| Analizada | Media (5.4) | 0.25% | — | Sysadminsmedia Homebox | 3/3/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicious HTML or SVG… | |
| Analizada | Media (6.7) | 0.13% | — | Mediatek Nbiot SDK | 2/3/2026 | 17/6/2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00473802; Issue ID: MSV-5970. | |
| Analizada | Alta (7.5) | 0.23% | — | Mediatek Lr12aMediatek Lr13Mediatek Nr15Mediatek Nr16+1 | 2/3/2026 | 17/6/2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:… | |
| Analizada | Alta (8.8) | 0.24% | — | Mediatek Software Development KITOpenwrt | 2/3/2026 | 17/6/2026 | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00467553; Issue ID: MSV-5151. | |
| Modificada | Alta (7.8) | 0.13% | — | Mediatek Nbiot SDK | 2/3/2026 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themeex Lorem Ipsum Books Media StoreAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11. | |
| Aplazada | Alta (7.1) | 0.28% | — | Atlasgondal Export Media UrlsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atlas Gondal Export Media URLs export-media-urls allows Reflected XSS.This issue affects Export Media URLs: from n/a through <= 2.2. | |
| Aplazada | Baja (3.8) | 0.24% | — | Creativeinteractivemedia Real 3D FlipbookAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Rtcamp Rtmedia FOR Wordpress Buddypress AND BbpressAI | 19/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8. |