Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)72%⚠ Explotación activa💥 PoCTj-actions Changed-files15/3/202524/9/2026
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
AplazadaAlta (7.1)0.15%💥 PoCNGO Thang IT PPO Call TO ActionsAI21/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue affects PPO Call To Actions: from n/a through <= 0.1.3.
AplazadaAlta (7.1)0.32%—Areteit Post AND Page ReactionsAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And Page Reactions post-and-page-reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through <= 1.0.5.
AnalizadaAlta (8.8)0.45%—Cmorillas1 External Database Based Actions15/11/202417/6/2026
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
AplazadaMedia (6.5)0.25%—Daniele Alessandra DA ReactionsAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniele Alessandra Da Reactions da-reactions allows Stored XSS.This issue affects Da Reactions: from n/a through <= 5.1.5.
ModificadaAlta (7.5)3.2%💥 ExploitGithub Actions/artifactGithub Actions Toolkit2/9/202417/6/2026
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that…
AplazadaMedia (4.3)0.40%—Discourse ReactionsAI15/4/202417/6/2026
Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data are shown on the `/u/:username/activity/reactions` endpoint.
AplazadaAlta (7.1)0.40%—Michael Simpson ADD Shortcodes Actions AND FiltersAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Add Shortcodes Actions And Filters allows Reflected XSS.This issue affects Add Shortcodes Actions And Filters: from n/a through 2.10.
ModificadaBaja (3.5)0.31%—Discourse Reactions12/1/202417/6/2026
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.
ModificadaAlta (8.8)2.6%—Tj-actions Verify-changed-files29/12/202317/6/2026
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow…
ModificadaCrítica (9.8)3.4%—Tj-actions Changed-files27/12/202317/6/2026
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue may lead to arbitrary command execution…
ModificadaCrítica (9.8)1.4%—Tj-actions Branch-names5/12/202317/6/2026
tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions `run` step. The head ref variable is the…
ModificadaAlta (8.8)0.32%—Wpreactions WP Reactions Lite9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions.
ModificadaMedia (6.1)0.33%—ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters26/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
AnalizadaAlta (8.8)0.26%—ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
ModificadaMedia (4.3)0.56%—Vuukle Comments, Reactions, Share Bar, Revenue12/7/202317/6/2026
The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for…
ModificadaAlta (8.8)0.27%—Areteit Activity Reactions FOR Buddypress23/4/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions.
ModificadaMedia (5.3)0.43%—Discourse Reactions19/4/202317/6/2026
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable…
ModificadaMedia (4.8)0.68%—ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters23/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress.
ModificadaMedia (6.5)0.51%—Actions-semi Ats2819p FirmwareActions-semi Ats2815 FirmwareActions-semi Ats2819 FirmwareActions-semi Ats2819s Firmware+130/11/202117/6/2026
The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown of a device by flooding the target device with LMP_features_res packets.
ModificadaMedia (5.4)0.65%—Wpreactions WP Reactions Lite1/11/202117/6/2026
The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.
ModificadaMedia (5.3)0.93%—Discourse Reactions19/10/202117/6/2026
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who are unable to update are advised to…
ModificadaMedia (6.5)0.44%—Actions-semi Ats2819p FirmwareActions-semi Ats2815 FirmwareActions-semi Ats2819 FirmwareActions-semi Ats2819s Firmware+17/9/202117/6/2026
The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that…
ModificadaMedia (6.5)0.44%—Actions-semi Ats2819p FirmwareActions-semi Ats2815 FirmwareActions-semi Ats2819 FirmwareActions-semi Ats2819s Firmware+17/9/202117/6/2026
The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via crafted LMP packets. Manual user intervention is required to…
ModificadaMedia (6.5)0.48%—Actions-micro Ezcast PRO II Firmware16/10/202017/6/2026
In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access the administration panel of the device.
Orbitaley — Vulnerabilidades