Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.58% | — | Themerex Edge DecorAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Edge Decor edge-decor allows PHP Local File Inclusion.This issue affects Edge Decor: from n/a through <= 2.2. | |
| Analizada | Media (6.9) | 0.29% | — | Tp-link Deco Be25 Firmware | 2/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authenticated adjacent attacker to read arbitrary files or cause denial of service. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822. | |
| Analizada | Alta (8.5) | 0.31% | — | Tp-link Deco Be25 Firmware | 2/3/2026 | 17/6/2026 | Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This… | |
| Analizada | Alta (7.7) | 0.23% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.… | |
| Analizada | Baja (2) | 0.36% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow… | |
| Aplazada | Media (6.3) | 0.14% | — | AMD Video Decoder Engine FirmwareAI | 12/2/2026 | 17/6/2026 | Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system. | |
| Aplazada | Alta (7.1) | 0.27% | — | Dmytro Shteflyuk CodecolorerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmytro Shteflyuk CodeColorer codecolorer allows Stored XSS.This issue affects CodeColorer: from n/a through <= 0.10.1. | |
| Aplazada | Baja (2.9) | 0.32% | — | Decocms MeshAI | 14/12/2025 | 30/9/2026 | A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argument domain causes improper access controls. The attack can be initiated remotely.… | |
| Aplazada | Media (4.3) | 0.21% | — | Webtoffee Decorator-woocommerce-email-customizerAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1. | |
| Aplazada | Media (5.3) | 0.28% | — | Accessiy BY Codeconfig AccessibilityAI | 6/12/2025 | 17/6/2026 | The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in versions up to, and including, 1.0.0. This is due to the plugin not performing capability checks in the `Settings::createPage()` function. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.25% | — | Accessiy BY Codeconfig AccessibilityAI | 6/12/2025 | 17/6/2026 | The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible… | |
| Aplazada | Baja (2.1) | 0.32% | 💥 PoC | Deco-cxAI | 1/12/2025 | 3/9/2026 | A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation of the argument url leads to server-side request forgery. The attack can be… | |
| Analizada | Media (5.7) | 0.20% | — | Sencore Decoder-ccv2 FirmwareSencore Smp100 FirmwareSencore En2sdi-2hd Firmware | 18/11/2025 | 17/6/2026 | The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint… | |
| Analizada | Media (6.5) | 0.37% | 💥 PoC | Nwaples Rardecode | 10/10/2025 | 17/6/2026 | github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash. | |
| Aplazada | Alta (8) | 1.6% | — | Tp-link Deco Be65 PROAI | 11/4/2025 | 17/6/2026 | OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device. | |
| Analizada | Media (5.3) | 0.42% | — | Code4berry Decoration Management System | 20/11/2024 | 17/6/2026 | A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /decoration/admin/btndates_report.php of the component Between Dates Reports. The manipulation of the argument fromdate/todate leads to sql injection. The attack… | |
| Analizada | Media (5.3) | 0.31% | — | Code4berry Decoration Management System | 20/11/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This affects an unknown part of the file /decoration/admin/user_permission.php of the component User Permission Handler. The manipulation leads to permission issues. It is possible to initiate the attack… | |
| Analizada | Media (5.3) | 0.32% | — | Code4berry Decoration Management System | 20/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unknown functionality of the file /decoration/admin/userregister.php of the component User Handler. The manipulation leads to permission issues. The attack may be launched… | |
| Analizada | Media (5.3) | 0.39% | — | Code4berry Decoration Management System | 20/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /decoration/admin/update_image.php of the component User Image Handler. The manipulation of the argument productimage1 leads to improper access… | |
| Aplazada | Alta (8.8) | 0.50% | — | Deco.agency DE BrandingAI | 20/11/2024 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.3) | 0.52% | — | Udecode Plate-coreAIUdecode PlateAI | 20/9/2024 | 17/6/2026 | Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` property. These attributes are passed to the node component using… | |
| Aplazada | Alta (8.1) | 0.50% | — | Udecode Plate MediaAI | 15/7/2024 | 17/6/2026 | Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable to XSS if a custom parser allows `javascript:`, `data:` or `vbscript:` URLs to be embedded. Editors that do not use `urlParsers` and consume the… | |
| Analizada | Media (5.5) | 0.20% | — | Mranderson Base64 Encoder/decoder | 15/5/2024 | 29/7/2026 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Analizada | Baja (2.4) | 0.22% | — | Mranderson Base64 Encoder/decoder | 15/5/2024 | 29/7/2026 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Analizada | Media (4.8) | 0.75% | 💥 Exploit | Mranderson Base64 Encoder/decoder | 15/5/2024 | 29/7/2026 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |