Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Wpthemespace Magical Addons FOR Elementor | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34. | |
| Modificada | Media (6.1) | 0.33% | — | Metagauss Registrationmagic | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.3.2.0. | |
| Aplazada | Alta (8.4) | 0.23% | — | Deepmagic DmitryAI | 30/4/2024 | 17/6/2026 | DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE-2017-7938. | |
| Modificada | Media (6.5) | 0.36% | — | Metagauss Registrationmagic | 24/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.1.9.2. | |
| Modificada | Alta (7.5) | 0.46% | — | Metagauss Registrationmagic | 24/4/2024 | 17/6/2026 | Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2. | |
| Modificada | Crítica (9.8) | 0.40% | — | Metagauss Registrationmagic | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9. | |
| Modificada | Alta (8.8) | 0.89% | — | Metagauss Registrationmagic | 9/4/2024 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.82% | — | Metagauss Registrationmagic | 9/4/2024 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of the RM_Form shortcode in all versions up to, and including, 5.3.1.0 due to insufficient escaping on the user supplied parameter and lack of… | |
| Modificada | Media (4.3) | 0.22% | — | Metagauss Registrationmagic | 26/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0. | |
| Analizada | Crítica (9.8) | 1.2% | — | Magicflue | 22/3/2024 | 17/6/2026 | File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint. | |
| Modificada | Media (6.1) | 0.42% | — | Metagauss Registrationmagic | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.2.5.9. | |
| Modificada | Media (5.5) | 0.22% | — | Samsung Magician | 7/2/2024 | 17/6/2026 | Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data. | |
| Modificada | Media (6.5) | 0.38% | — | Magicsoftware Magic XPI Integration Platform | 6/2/2024 | 17/6/2026 | The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport. | |
| Modificada | Media (6.1) | 0.35% | — | Metagauss Registrationmagic | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment,… | |
| Modificada | Baja (2.4) | 1.2% | 💥 PoC | Apple Magic Keyboard Firmware | 12/1/2024 | 17/6/2026 | A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic. | |
| Modificada | Media (5.5) | 0.17% | — | ZTE Redmagic 8 PRO Firmware | 4/1/2024 | 17/6/2026 | Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro | |
| Modificada | Alta (8.8) | 0.82% | — | Ssssssss Magic-api | 2/1/2024 | 17/6/2026 | A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resource/file/api/save?auto=1. The manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (5.5) | 0.16% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service. | |
| Modificada | Alta (7.1) | 0.16% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | |
| Modificada | Alta (7.8) | 0.20% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution. | |
| Modificada | Media (5.5) | 0.13% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | |
| Modificada | Media (5.5) | 0.17% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. | |
| Modificada | Media (5.5) | 0.15% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | |
| Modificada | Media (5.5) | 0.15% | — | Hihonor Magic OS | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | |
| Modificada | Alta (7.1) | 0.16% | — | Hihonor Magic OS | 29/12/2023 | 17/6/2026 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. |