Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.14% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method. | |
| Aplazada | Media (5.4) | 0.23% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method. | |
| Aplazada | Alta (8.7) | 0.95% | — | Elixir PlugAI | 23/6/2026 | 23/6/2026 | Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Conn.Query.decode/4 (and Plug.Conn.Query.decode_each/2) parse query strings and application/x-www-form-urlencoded request bodies. When a key contains many bracketed segments… | |
| Aplazada | Crítica (9.1) | 0.52% | — | Mojolicious Plugin WEB Auth Oauth2AI | 23/6/2026 | 23/6/2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)… | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Media (5.3) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 18/6/2026 | 18/6/2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by… | |
| Aplazada | Crítica (9.1) | 0.33% | — | Dancer2 Plugin Auth OauthAI | 15/6/2026 | 17/6/2026 | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable. | |
| Aplazada | Alta (7.5) | 0.42% | — | Booking-wp-plugin BooklyAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | Weplugins WP MapsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions. | |
| Pendiente de análisis | Alta (7.6) | 0.70% | — | Gstreamer Gst-plugins-goodAI | 15/6/2026 | 3/8/2026 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 8/9/2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 5/8/2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel… | |
| Pendiente de análisis | Alta (7.1) | 0.63% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing… | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1… | |
| Analizada | Alta (8.5) | 0.81% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 14/6/2026 | 23/7/2026 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Aplazada | Alta (7.2) | 0.32% | 💥 PoC | Booking-wp-plugin BooklyAI | 13/6/2026 | 23/7/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Fooplugins FoogalleryAI | 13/6/2026 | 23/7/2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of… | |
| Pendiente de análisis | Media (6.5) | 0.40% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three… | |
| Aplazada | Media (5.9) | 0.18% | — | Membraneframework Membrane MP4 PluginAI | 11/6/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion. The MP4 box header parser converts each 4-byte box name to an atom using String.to_atom/1 without validation.… | |
| Aplazada | Media (5.3) | 0.24% | — | Essentialplugin WP Logo Showcase Responsive Slider AND CarouselAI | 11/6/2026 | 23/7/2026 | Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 9/6/2026 | 28/8/2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 9/6/2026 | 28/8/2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |