Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Wpcompress WP CompressAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28. | |
| Analizada | Alta (7.8) | 0.35% | — | Node-modules Compressing | 4/2/2026 | 17/6/2026 | Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outside the intended extraction directory, an attacker can cause subsequent file… | |
| Aplazada | Media (4.6) | 0.15% | — | Muntashirakon AppmanagerAIApache Commons CompressAI | 27/1/2026 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/archivers/tar modules). This vulnerability is associated with program files TarUtils.Java. This issue affects AppManager: before 4.0.4. | |
| Aplazada | Alta (7.1) | 0.21% | — | Agmorpheus Syntax Highlighter CompressAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agmorpheus Syntax Highlighter Compress syntax-highlighter-compress allows Reflected XSS.This issue affects Syntax Highlighter Compress: from n/a through <= 3.0.83.3. | |
| Aplazada | Media (5.3) | 0.32% | — | Wpcompress WP Compress FOR MainwpAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.50.17. | |
| Analizada | Media (6.3) | 0.53% | — | Airlift Aircompressor | 12/12/2025 | 1/10/2026 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted compressed… | |
| Analizada | Alta (8.8) | 0.28% | — | Apple Compressor | 13/11/2025 | 17/6/2026 | The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a Compressor server may be able to execute arbitrary code. | |
| Aplazada | Baja (2.4) | 0.12% | — | Intel Neural CompressorAI | 11/11/2025 | 17/6/2026 | Improper neutralization for some Intel(R) Neural Compressor software before version v3.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (4.1) | 0.32% | — | Wpmudev Smush Image Compression AND OptimizationAI | 6/11/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0. | |
| Aplazada | Media (5.3) | 0.46% | — | Wpcompress WP CompressAI | 22/9/2025 | 30/9/2026 | Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Compress: from n/a through <= 6.50.54. | |
| Analizada | Baja (3.8) | 0.29% | — | Eliehanna Compress & Upload | 9/9/2025 | 10/7/2026 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 0.38% | — | Wpcompress WP Compress | 4/7/2025 | 17/6/2026 | Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This issue affects WP Compress: from n/a through <= 6.30.30. | |
| Aplazada | Media (4.3) | 0.35% | — | Zara 4 Image CompressionAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zara 4 Image Compression: from n/a through <= 1.2.17.2. | |
| Aplazada | Media (5.4) | 0.30% | — | Wpcompress WP Compress FOR MainwpAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.30.32. | |
| Aplazada | Crítica (9.8) | 0.63% | — | Google BrotliAIPerl IO Compress BrotliAI | 30/5/2025 | 17/6/2026 | A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash,… | |
| Modificada | Alta (8.8) | 0.17% | — | Wpcompress WP Compress | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Request Forgery.This issue affects WP Compress: from n/a through <= 6.30.30. | |
| Aplazada | Alta (7.1) | 0.21% | — | Regen Script CompressorAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in regen Script Compressor script-compressor allows Stored XSS.This issue affects Script Compressor: from n/a through <= 1.7.1. | |
| Aplazada | Media (5.3) | 0.50% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through… | |
| Aplazada | Media (4.9) | 0.18% | — | Wpcompress WP Compress FOR MainwpAI | 28/3/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Server Side Request Forgery.This issue affects WP Compress for MainWP: from n/a through <= 6.30.03. | |
| Aplazada | Media (4.3) | 0.28% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a… | |
| Analizada | Alta (8.8) | 0.45% | — | Wpcompress WP Compress | 26/3/2025 | 17/6/2026 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.15. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.8) | 0.39% | — | Wpcompress WP Compress | 25/3/2025 | 17/6/2026 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web… | |
| Aplazada | Media (4.3) | 0.17% | — | Hosting.io JPG PNG Compression AND OptimizationAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hosting.io JPG, PNG Compression and Optimization wp-image-compression allows Cross Site Request Forgery.This issue affects JPG, PNG Compression and Optimization: from n/a through <= 1.7.35. | |
| Analizada | Media (5.1) | 0.39% | — | Rems Image Compressor Tool | 11/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The manipulation of the argument image leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.13% | — | Intel Neural CompressorAI | 16/1/2025 | 17/6/2026 | Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access. |