Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.64% | — | Sunnykai AI MagicAI | 31/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in SunnyKai AI Magic newsletter-page-redirects allows Privilege Escalation.This issue affects AI Magic: from n/a through <= 1.0.4. | |
| Analizada | Media (5.5) | 0.15% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.15% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.12% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.16% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Media (5.5) | 0.14% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Media (5.5) | 0.15% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Analizada | Alta (7.8) | 0.17% | — | Honor Magicos | 26/12/2024 | 17/6/2026 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | |
| Aplazada | Media (6.4) | 0.35% | — | MagicpostAI | 21/12/2024 | 17/6/2026 | The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.1) | 0.29% | — | Magicwinmail Winmail Server | 18/12/2024 | 17/6/2026 | Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 0.57% | — | Metagauss Registrationmagic | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 5.2.3.0. | |
| Modificada | Media (5.4) | 0.26% | — | Wpthemespace Magical Addons FOR Elementor | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through <= 1.3.6. | |
| Analizada | Baja (2.8) | 0.17% | — | Samsung Magician | 3/12/2024 | 17/6/2026 | An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process. | |
| Aplazada | Media (6.5) | 0.32% | — | Webvitaly Magic SliderAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Magic Slider magic-slider allows Stored XSS.This issue affects Magic Slider: from n/a through <= 1.3. | |
| Analizada | Media (4.3) | 0.34% | — | Wpthemespace Magical Addons FOR Elementor | 9/11/2024 | 17/6/2026 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the get_content_type function in includes/widgets/content-reveal.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Crítica (9.8) | 1.5% | 💥 PoC | Metagauss Registrationmagic | 9/11/2024 | 17/6/2026 | The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password.… | |
| Modificada | Media (4.3) | 0.57% | 💥 PoC | Wpthemespace Magical Addons FOR Elementor | 4/11/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through <= 1.2.1. | |
| Analizada | Alta (7.3) | 0.91% | 💥 Exploit | Magicbug Cloudlog | 14/10/2024 | 17/6/2026 | Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. | |
| Analizada | Crítica (9.8) | 0.44% | — | Magicbug Cloudlog | 14/10/2024 | 17/6/2026 | Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. | |
| Analizada | Crítica (9.8) | 0.44% | — | Magicbug Cloudlog | 14/10/2024 | 17/6/2026 | Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. |