Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1720 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.36%—Magicbug Cloudlog1/10/202417/6/2026
A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.
AnalizadaMedia (6.1)0.31%—Magic-post-thumbnail Magic Post Thumbnail29/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9.
AnalizadaMedia (6.1)0.27%—Metagauss Registrationmagic19/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects RegistrationMagic: from n/a through 6.0.1.0.
ModificadaCrítica (9.8)0.56%—H3C Magic B1st Firmware16/8/202417/6/2026
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
AnalizadaMedia (4.8)0.40%—Magic-post-thumbnail Magic Post Thumbnail13/8/202417/6/2026
The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaCrítica (9.8)92%⚠ Explotación activa💥 ExploitSamsung Magicinfo 9 Server12/8/20241/10/2026
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
AnalizadaMedia (6.1)0.27%—Metagauss Registrationmagic1/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RegistrationMagic Forms RegistrationMagic allows Stored XSS.This issue affects RegistrationMagic: from n/a through 6.0.0.1.
AnalizadaAlta (7.8)0.93%💥 PoCImagemagick29/7/202417/6/2026
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading…
ModificadaMedia (6.4)0.21%—Wpthemespace Magical Addons FOR Elementor22/7/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
AplazadaMedia (6.5)0.25%—Noor Alam Magical Posts Display Elementor Gutenberg Posts BlocksAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor alam Magical Posts Display – Elementor & Gutenberg Posts Blocks allows Stored XSS.This issue affects Magical Posts Display – Elementor & Gutenberg Posts Blocks: from n/a through 1.2.38.
AnalizadaMedia (5.4)0.32%—Wpthemespace Magical Addons FOR Elementor20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
AplazadaAlta (8.8)0.33%—H3C Technologies Magic Rc3000AI16/7/202417/6/2026
An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing functionality.
ModificadaCrítica (9.1)0.82%—Magiclen Stringbuilder10/7/202417/6/2026
All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative…
AnalizadaMedia (4.1)0.41%—H3C Magic R230 Firmware24/6/202417/6/2026
H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
AnalizadaCrítica (9.8)0.53%—H3C Magic R230 Firmware24/6/202417/6/2026
H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
AnalizadaMedia (6.3)0.14%—Samsung Magician20/6/202417/6/2026
Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path.
ModificadaMedia (5.4)0.31%—Andibauer Svgmagic14/6/202417/6/2026
The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
ModificadaMedia (5.4)0.31%—Wpthemespace Magical Addons FOR Elementor6/6/202417/6/2026
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This makes…
AnalizadaMedia (5.3)0.33%—Metagauss Registrationmagic4/6/202417/6/2026
Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
AnalizadaAlta (7.5)0.38%—Metagauss Registrationmagic4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
AplazadaMedia (5.9)0.26%—Hans VAN Eijsden Imagemagick Sharpen Resized ImagesAI3/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue affects ImageMagick Sharpen Resized Images: from n/a through 1.1.7.
AplazadaAlta (7.5)0.42%—H3C Magic R365AIH3C Magic R100AI28/5/202417/6/2026
An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service.
AnalizadaMedia (6.7)0.14%—Samsung Magician14/5/202417/6/2026
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password…
AnalizadaMedia (6.7)0.17%—Samsung Magician14/5/202417/6/2026
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation…
ModificadaMedia (5.4)0.27%—Wpthemespace Magical Addons FOR Elementor14/5/202417/6/2026
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping…