Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.47% | — | Liuyueyi Quick-mediaAIApache BatikAI | 27/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java. This issue affects quick-media: before v1.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Sully Media Library File SizeAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Sully Media Library File Size media-library-file-size allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library File Size: from n/a through <= 1.6.7. | |
| Aplazada | Alta (7.5) | 0.45% | — | Softwebmedia Gyan ElementsAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements gyan-elements allows PHP Local File Inclusion.This issue affects Gyan Elements: from n/a through <= 2.2.1. | |
| Aplazada | Alta (7.5) | 0.32% | — | Fastlinemedia Beaver BuilderAI | 22/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Code Injection.This issue affects Beaver Builder: from n/a through <= 2.9.4.1. | |
| Aplazada | Alta (7.1) | 0.27% | — | Designingmedia HostikoAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko hostiko allows Reflected XSS.This issue affects Hostiko: from n/a through < 94.3.6. | |
| Aplazada | Crítica (9.9) | 14% | — | Zoom Node Multimedia RoutersAI | 20/1/2026 | 17/6/2026 | A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access. | |
| Aplazada | Media (4.8) | 0.41% | — | Videolan VLC Media PlayerAI | 16/1/2026 | 17/6/2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server. | |
| Aplazada | Media (6.7) | 0.41% | — | Leawo Prof. MediaAI | 16/1/2026 | 17/6/2026 | Leawo Prof. Media 11.0.0.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized payload in the activation keycode field. Attackers can generate a 6000-byte buffer of repeated characters to trigger an application crash when pasted into the registration… | |
| Analizada | Media (5.3) | 0.27% | — | Wikimedia Campaignevents | 9/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Baja (2.3) | 0.37% | — | Wikimedia Mediawiki Monaco SkinAI | 9/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Monaco Skin allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Monaco Skin: 1.45, 1.44, 1.43, 1.39. | |
| Analizada | Baja (2.3) | 0.19% | — | Wikimedia Wikibase | 9/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Media (6.5) | 0.20% | — | Buddydev MediapressAI | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress mediapress allows Stored XSS.This issue affects MediaPress: from n/a through <= 1.6.2. | |
| Aplazada | Media (5.3) | 0.21% | — | Ideabox Creations Dashboard Welcome FOR Beaver BuilderAIFastlinemedia Beaver BuilderAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Welcome for Beaver Builder: from n/a through <= 1.0.8. | |
| Analizada | Media (6.1) | 0.24% | — | Wikimedia Mediawiki-extensions-uploadwizard | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Media (5.4) | 0.26% | — | Easy Media DownloadAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Download easy-media-download allows Reflection Injection.This issue affects Easy Media Download: from n/a through <= 1.1.11. | |
| Aplazada | Media (4.9) | 0.14% | — | Minnur External MediaAI | 7/1/2026 | 7/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forgery.This issue affects External Media: from n/a through <= 1.0.36. | |
| Analizada | Media (4.9) | 0.31% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 7/1/2026 | 7/10/2026 | Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface. | |
| Analizada | Baja (3.3) | 0.09% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 7/1/2026 | 7/10/2026 | Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests. | |
| Analizada | Media (4.3) | 0.20% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 7/1/2026 | 7/10/2026 | Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods. | |
| Aplazada | Alta (8.8) | 0.33% | — | Dasinfomedia WpchurchAI | 7/1/2026 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0. | |
| Aplazada | Alta (7.7) | 0.27% | — | Najeebmedia Frontend File ManagerAI | 7/1/2026 | 7/10/2026 | The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server | |
| Aplazada | Alta (7.1) | 0.18% | — | Dasinfomedia WpchurchAI | 7/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHURCH allows Reflected XSS.This issue affects WPCHURCH: from n/a through 2.7.0. | |
| Aplazada | Alta (8.6) | 0.31% | — | Qihang Media WEB Digital SignageAI | 6/1/2026 | 17/6/2026 | QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication… | |
| Aplazada | Alta (8.7) | 1.4% | — | Cayin Signage Media PlayerAI | 6/1/2026 | 17/6/2026 | Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root. | |
| Aplazada | Media (6.4) | 0.18% | — | MediapressAI | 6/1/2026 | 17/6/2026 | The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |