Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (1.6) | 0.13% | — | Vaadin Flow Maven PluginAIVaadin Flow Gradle PluginAIVaadin Flow Plugin BaseAI | 19/5/2026 | 14/9/2026 | A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any… | |
| Aplazada | Alta (7.5) | 0.47% | — | Weplugins WP MapsAI | 18/5/2026 | 17/6/2026 | The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks. | |
| Aplazada | Media (6.9) | 0.23% | — | Mybb Timeline PluginAI | 16/5/2026 | 17/6/2026 | MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change… | |
| Analizada | Crítica (9.1) | 0.35% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Media (5.5) | 0.14% | — | Freedesktop Gst-plugins-good | 14/5/2026 | 17/6/2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero. | |
| Analizada | Media (4.3) | 0.28% | — | Linuxfoundation Backstage/plugin-catalog-backend-module-unprocessedLinuxfoundation Backstage/plugin-catalog-unprocessed-entitiesLinuxfoundation Backstage/plugin-catalog-unprocessed-entities-common | 14/5/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is… | |
| Aplazada | Alta (8.2) | 0.85% | — | Plug Project PlugAI | 14/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper bound on the size of the… | |
| Aplazada | Alta (8.4) | 0.26% | — | Juno Network JunoclawlAIJuno Network Plugin ShellAI | 12/5/2026 | 17/6/2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check could be bypassed by adversarial argument constructions, allowing unauthorized command execution on the host when combined with the companion advisory. Pre-patch, the… | |
| Aplazada | Alta (8.4) | 0.22% | — | Juno Network JunoclawfastaioAIJuno Network Plugin ShellAI | 12/5/2026 | 17/6/2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument string to the shell's parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command… | |
| Aplazada | Media (4.9) | 0.29% | — | Wpsemplugins WP SEO Structured Data SchemaAI | 12/5/2026 | 17/6/2026 | The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (6.2) | 0.43% | — | Getgrav Grav-plugin-adminAI | 11/5/2026 | 17/6/2026 | grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly validate and sanitize user input in the data[header][title] parameter. As a result, attackers can craft a… | |
| Analizada | Alta (8.8) | 0.49% | — | Getgrav Grav-plugin-api | 11/5/2026 | 17/6/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API plugin (UsersController::update) allows any authenticated user with… | |
| Aplazada | Alta (7.5) | 0.36% | — | Catalyst Plugin StatsdAI | 10/5/2026 | 24/7/2026 | Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids may be leaked. This may allow an attacker to use session ids as authentication… | |
| Pendiente de análisis | Media (5.3) | 0.52% | — | Cpanel Nova PluginAI | 8/5/2026 | 17/6/2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home… | |
| Analizada | Baja (2.3) | 0.38% | — | Absinthe-graphql Absinthe.plug | 8/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.Plug.GraphiQL':js_escape/1 in lib/absinthe/plug/graphiql.ex escapes single quotes and newlines in the query GET parameter… | |
| Aplazada | Media (4.3) | 0.14% | — | Pluginus BearAI | 7/5/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affects BEAR: from n/a through 1.1.5. | |
| Aplazada | Media (5.3) | 0.31% | — | Bplugins PDF PosterAI | 7/5/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1. | |
| Analizada | Media (6.9) | 0.14% | — | HP Samsung Print Service Plugin | 6/5/2026 | 17/6/2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Crítica (9.8) | 0.84% | 💥 PoC | Pickplugins User VerificationAI | 2/5/2026 | 17/6/2026 | The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.24% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 30/4/2026 | 17/6/2026 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's… | |
| Aplazada | Media (5.3) | 0.44% | — | Really-simple-plugins ComplianzAI | 29/4/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any… | |
| Aplazada | Media (5.5) | 0.61% | — | Douinc Mkdocs-mcp-pluginAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Performing a manipulation of the argument docs_dir/file_path results in path traversal. The attack is possible to be carried out remotely. The exploit has been made public… | |
| Analizada | Alta (8.7) | 0.78% | — | Elixir-plug Plug.cowboy | 27/4/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table exhaustion. Plug.Cowboy.Conn.conn/1 in lib/plug/cowboy/conn.ex calls String.to_atom/1 on the value returned by :cowboy_req.scheme/1. For HTTP/2 connections,… | |
| Analizada | Alta (8.4) | 0.18% | — | Liveon Canonnwcamplugin.exeLiveon Canonnwcampluginforadmin.exeLiveon Downloader5installer.exeLiveon Downloader5installerforadmin.exe | 23/4/2026 | 17/6/2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory,… |