Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.0% | — | Benjaminrojas WP Editor | 17/4/2025 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which… | |
| Aplazada | Media (4.3) | 0.19% | — | Yuya Hoshino Bulk Term EditorAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yuya Hoshino Bulk Term Editor bulk-term-editor allows Cross Site Request Forgery.This issue affects Bulk Term Editor: from n/a through <= 1.1.4. | |
| Modificada | Alta (7.8) | 0.29% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+13 | 15/4/2025 | 17/6/2026 | A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Aplazada | Alta (7.1) | 0.34% | — | Twispay Credit Card PaymentsAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in twispay Twispay Credit Card Payments twispay allows Reflected XSS.This issue affects Twispay Credit Card Payments: from n/a through <= 2.1.2. | |
| Aplazada | Media (5.9) | 0.40% | — | Benjamin Chris WP EditormdAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor wp-editormd allows Stored XSS.This issue affects WP Editor.md – The Perfect WordPress Markdown Editor: from n/a through <= 10.2.1. | |
| Aplazada | Alta (8.8) | 0.25% | — | Wpfront User Role EditorAI | 8/4/2025 | 17/6/2026 | The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.1. This is due to missing or incorrect nonce validation on the whitelist_options() function. This makes it possible for unauthenticated attackers to update the default role option… | |
| Aplazada | Media (6.5) | 0.38% | — | Richtexteditor Rich Text EditorAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.38% | — | Enituretechnology Small Package Quotes Worldwide Express EditionAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.19. | |
| Aplazada | Alta (7.1) | 0.39% | — | Enituretechnology Small Package Quotes WWE EditionAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Reflected XSS.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.18. | |
| Aplazada | Crítica (10) | 0.68% | — | Kellydiek Digiwidgets Image EditorAI | 1/4/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote Code Inclusion.This issue affects DigiWidgets Image Editor: from n/a through <= 1.10. | |
| Aplazada | Media (4.3) | 0.21% | — | Itpathsolutions Scss WP EditorAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in IT Path Solutions SCSS WP Editor scss-wp-editor allows Cross Site Request Forgery.This issue affects SCSS WP Editor: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.40% | — | Termel Bulk Fields EditorAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in termel Bulk Fields Editor bulk-user-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Fields Editor: from n/a through <= 1.8.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Richtexteditor Rich Text EditorAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor richtexteditor allows Stored XSS.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.23% | — | Disable Elementor Editor TranslationAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from n/a through <= 1.0.2. | |
| Analizada | Baja (3.3) | 0.12% | — | Splunk APP FOR Lookup File Editing | 26/3/2025 | 17/6/2026 | In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user. | |
| Aplazada | Crítica (9.9) | 0.78% | — | Govind Visual Text EditorAI | 26/3/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.This issue affects Visual Text Editor: from n/a through <= 1.2.1. | |
| Aplazada | Alta (7.1) | 0.36% | — | Wpsiteeditor Site Editor Google MAPAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsiteeditor Site Editor Google Map site-editor-google-map allows Reflected XSS.This issue affects Site Editor Google Map: from n/a through <= 1.0.1. | |
| Analizada | Alta (7.8) | 0.28% | — | Pdf-xchange Pdf-toolsPdf-xchange Editor | 24/3/2025 | 17/6/2026 | PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Media (5.1) | 0.38% | — | Dante-editor Dante3 | 24/3/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (4.3) | 0.17% | — | Benjamin Pick Contact Form 7 Select BOX Editor ButtonAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Benjamin Pick Contact Form 7 Select Box Editor Button contact-form-7-select-box-editor-button allows Cross Site Request Forgery.This issue affects Contact Form 7 Select Box Editor Button: from n/a through <= 0.6. | |
| Modificada | Media (6.1) | 0.15% | — | Ppdpurveyor Google News Editors Picks Feed Generator | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator google-news-editors-picks-news-feeds allows Stored XSS.This issue affects Google News Editors Picks Feed Generator: from n/a through <= 2.1. | |
| Analizada | Baja (3.3) | 0.24% | — | Pdf-xchange Pdf-toolsPdf-xchange EditorPdf-xchange PRO | 11/3/2025 | 17/6/2026 | PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Aplazada | Media (5.3) | 0.38% | — | Beijing Founder Electronics Founder Enjoys All-media Acquisition AND Editing SystemAI | 9/3/2025 | 17/6/2026 | A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affected by this issue is the function electricDocList of the file /newsedit/report/reportCenter.do. The manipulation of the argument fvID/catID leads to sql injection. The… | |
| Aplazada | Media (5.3) | 0.41% | — | Beijing Founder Electronics Founder Enjoys All-media Acquisition AND Editing SystemAI | 9/3/2025 | 17/6/2026 | A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /newsedit/newsedit/xy/imageProxy.do of the component File Protocol Handler. The manipulation of… | |
| Aplazada | Crítica (10) | 0.39% | — | Opentext Identity Manager Advanced EditionAI | 5/3/2025 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager… |