Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.31% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.27% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Media (5.5) | 0.30% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 22/11/2024 | 17/6/2026 | PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Aplazada | Media (6.5) | 0.36% | — | Steven Nolles Bonway Static Block EditorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steven Nolles Bonway Static Block Editor bonway-static-block-editor allows DOM-Based XSS.This issue affects Bonway Static Block Editor: from n/a through <= 1.1.0. | |
| Modificada | Alta (8.8) | 0.62% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 14/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3. | |
| Aplazada | Media (6.1) | 0.35% | — | Froala Wysiwyg EditorAI | 7/11/2024 | 17/6/2026 | Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier. | |
| Modificada | Alta (8.8) | 0.37% | — | Wpchill Htaccess File Editor | 1/11/2024 | 17/6/2026 | Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Htaccess File Editor: from n/a through <= 1.0.18. | |
| Aplazada | Media (6.5) | 0.27% | — | Faceleg Raptor EditorAI | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faceleg Raptor Editor wp-raptor allows DOM-Based XSS.This issue affects Raptor Editor: from n/a through <= 1.0.20. | |
| Aplazada | Media (6.4) | 0.34% | — | Editor Custom Color PaletteAI | 26/10/2024 | 17/6/2026 | The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Crítica (9.8) | 36% | 💥 PoC | WUX Blog EditorAI | 26/10/2024 | 17/6/2026 | The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Crítica (9.8) | 0.56% | — | WUX Blog EditorAI | 26/10/2024 | 17/6/2026 | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user. | |
| Aplazada | Media (4.3) | 0.28% | — | Sovrn Editorial AssistantAI | 26/10/2024 | 17/6/2026 | The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (8.6) | 0.50% | — | Ininet Solutions Spidercontrol Scada PC HMI EditorAI | 24/10/2024 | 17/6/2026 | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup… | |
| Aplazada | Alta (8.5) | 0.42% | — | Wpgrim Classic Editor AND Classic WidgetsAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Grim Classic Editor and Classic Widgets classic-editor-and-classic-widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through <= 1.4.1. | |
| Aplazada | Media (5.3) | 0.49% | — | D-zero CO LTD BurgereditorAID-zero CO LTD Burgereditor Limited EditionAIBasercmsAI | 11/10/2024 | 5/7/2026 | A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files. | |
| Aplazada | Alta (7.1) | 0.32% | — | Yellopencil Visual CSS Style EditorAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YellowPencil YellowPencil Visual CSS Style Editor yellow-pencil-visual-theme-customizer allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through <= 7.6.4. | |
| Analizada | Media (6.1) | 0.45% | — | Themehigh Checkout Field Editor FOR Woocommerce | 4/10/2024 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.4) | 0.16% | — | Foxit PDF ReaderAIFoxit PDF EditorAI | 26/9/2024 | 17/6/2026 | In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed. | |
| Modificada | Media (5.1) | 0.52% | — | Ckeditor5 | 25/9/2024 | 17/6/2026 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the… | |
| Analizada | Alta (7.2) | 0.58% | — | Benjaminrojas WP Editor | 13/9/2024 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call… | |
| Analizada | Alta (7.2) | 0.74% | — | Themeeditor Theme Editor | 29/8/2024 | 17/6/2026 | The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary… |