Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2470 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.26% | — | Burhan Nasir Smart Auto Upload ImagesAI | 19/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery.This issue affects Smart Auto Upload Images: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.4) | 0.16% | — | Easy Author ImageAI | 19/2/2026 | 17/6/2026 | The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_url' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (6.4) | 0.19% | — | Devvn Image HotspotAI | 19/2/2026 | 17/6/2026 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' custom field meta in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level access… | |
| Aplazada | Media (6.4) | 0.32% | — | Essentialplugin Album AND Image Gallery Plus LightboxAI | 19/2/2026 | 17/6/2026 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `aigpl-gallery-album` shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpchill Modula Image GalleryAI | 14/2/2026 | 17/6/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API. This makes it… | |
| Aplazada | Media (5.1) | 0.23% | — | Ricoh WEB Image MonitorAI | 12/2/2026 | 17/6/2026 | RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-site scripting attacks. | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 PoC | Manga Image TranslatorAI | 11/2/2026 | 14/7/2026 | manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled request bodies using pickle.loads() without… | |
| Aplazada | Media (4.4) | 0.26% | — | Category ImageAI | 11/2/2026 | 17/6/2026 | The Category Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag-image' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject… | |
| Aplazada | Alta (7.2) | 0.33% | — | ALL IN ONE Image Viewer BlockAI | 5/2/2026 | 17/6/2026 | The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Media (6.4) | 0.23% | — | Robin Image OptimizerAI | 5/2/2026 | 17/6/2026 | The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (4.9) | 0.59% | — | Shortpixel Image OptimizerAI | 5/2/2026 | 17/6/2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.3) | 0.32% | — | IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems | 4/2/2026 | 17/6/2026 | IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the… | |
| Analizada | Media (5.3) | 0.32% | — | IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems | 4/2/2026 | 17/6/2026 | IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Cloud PAK SystemIBM OS Image FOR RED HAT Linux Systems | 4/2/2026 | 17/6/2026 | IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system. | |
| Aplazada | Media (5.3) | 0.20% | — | Illid Share This ImageAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.09. | |
| Aplazada | Media (4.3) | 0.23% | — | Wpchill Modula Image GalleryAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image Gallery: from n/a through <= 2.13.6. | |
| Aplazada | Crítica (9.2) | 5.5% | 💥 Exploit | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… | |
| Aplazada | Media (4.3) | 0.28% | — | Easy Replace ImageAI | 28/1/2026 | 17/6/2026 | The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.5.2. This is due to missing capability checks on the `image_replacement_from_url` function that is hooked to the `eri_from_url` AJAX action. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (10) | 0.30% | — | Pilgrimage233 Minecraft-rcon-manageAI | 27/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Manage: before 3.0. | |
| Analizada | Crítica (9.8) | 0.92% | — | Remyandrade Modern Image Gallery APP | 23/1/2026 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.9. | |
| Aplazada | Media (5.4) | 0.30% | — | Cloudinary-image-management-and-manipulation-in-the-cloud-cdnAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Cloudinary Cloudinary cloudinary-image-management-and-manipulation-in-the-cloud-cdn allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cloudinary: from n/a through <= 3.3.2. | |
| Aplazada | Media (4.3) | 0.23% | — | Webdevstudios Automatic Featured Images From VideosAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.9) | 0.20% | — | Wpchill Modula Image GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4. | |
| Aplazada | Media (5.4) | 0.28% | — | Merkulove Comparimager FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1. |