Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 72% | ⚠ Explotación activa💥 PoC | Tj-actions Changed-files | 15/3/2025 | 24/9/2026 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.) | |
| Aplazada | Alta (7.1) | 0.15% | 💥 PoC | NGO Thang IT PPO Call TO ActionsAI | 21/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue affects PPO Call To Actions: from n/a through <= 0.1.3. | |
| Aplazada | Alta (7.1) | 0.32% | — | Areteit Post AND Page ReactionsAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And Page Reactions post-and-page-reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through <= 1.0.5. | |
| Analizada | Alta (8.8) | 0.45% | — | Cmorillas1 External Database Based Actions | 15/11/2024 | 17/6/2026 | The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Aplazada | Media (6.5) | 0.25% | — | Daniele Alessandra DA ReactionsAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniele Alessandra Da Reactions da-reactions allows Stored XSS.This issue affects Da Reactions: from n/a through <= 5.1.5. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Github Actions/artifactGithub Actions Toolkit | 2/9/2024 | 17/6/2026 | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that… | |
| Aplazada | Media (4.3) | 0.40% | — | Discourse ReactionsAI | 15/4/2024 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data are shown on the `/u/:username/activity/reactions` endpoint. | |
| Aplazada | Alta (7.1) | 0.40% | — | Michael Simpson ADD Shortcodes Actions AND FiltersAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Add Shortcodes Actions And Filters allows Reflected XSS.This issue affects Add Shortcodes Actions And Filters: from n/a through 2.10. | |
| Modificada | Baja (3.5) | 0.31% | — | Discourse Reactions | 12/1/2024 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939. | |
| Modificada | Alta (8.8) | 2.6% | — | Tj-actions Verify-changed-files | 29/12/2023 | 17/6/2026 | The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow… | |
| Modificada | Crítica (9.8) | 3.4% | — | Tj-actions Changed-files | 27/12/2023 | 17/6/2026 | tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue may lead to arbitrary command execution… | |
| Modificada | Crítica (9.8) | 1.4% | — | Tj-actions Branch-names | 5/12/2023 | 17/6/2026 | tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions `run` step. The head ref variable is the… | |
| Modificada | Alta (8.8) | 0.32% | — | Wpreactions WP Reactions Lite | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions. | |
| Modificada | Media (6.1) | 0.33% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |
| Analizada | Alta (8.8) | 0.26% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |
| Modificada | Media (4.3) | 0.56% | — | Vuukle Comments, Reactions, Share Bar, Revenue | 12/7/2023 | 17/6/2026 | The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.27% | — | Areteit Activity Reactions FOR Buddypress | 23/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions. | |
| Modificada | Media (5.3) | 0.43% | — | Discourse Reactions | 19/4/2023 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable… | |
| Modificada | Media (4.8) | 0.68% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 23/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress. | |
| Modificada | Media (6.5) | 0.51% | — | Actions-semi Ats2819p FirmwareActions-semi Ats2815 FirmwareActions-semi Ats2819 FirmwareActions-semi Ats2819s Firmware+1 | 30/11/2021 | 17/6/2026 | The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown of a device by flooding the target device with LMP_features_res packets. | |
| Modificada | Media (5.4) | 0.65% | — | Wpreactions WP Reactions Lite | 1/11/2021 | 17/6/2026 | The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages. | |
| Modificada | Media (5.3) | 0.93% | — | Discourse Reactions | 19/10/2021 | 17/6/2026 | Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who are unable to update are advised to… | |
| Modificada | Media (6.5) | 0.44% | — | Actions-semi Ats2819p FirmwareActions-semi Ats2815 FirmwareActions-semi Ats2819 FirmwareActions-semi Ats2819s Firmware+1 | 7/9/2021 | 17/6/2026 | The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that… | |
| Modificada | Media (6.5) | 0.44% | — | Actions-semi Ats2819p FirmwareActions-semi Ats2815 FirmwareActions-semi Ats2819 FirmwareActions-semi Ats2819s Firmware+1 | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via crafted LMP packets. Manual user intervention is required to… | |
| Modificada | Media (6.5) | 0.48% | — | Actions-micro Ezcast PRO II Firmware | 16/10/2020 | 17/6/2026 | In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access the administration panel of the device. |