Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.36%—Devsapp Fc-stable-diffusion22/5/202517/6/2026
Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.
AplazadaMedia (4.3)0.14%—Sanjeev Mohindra Author BOX With Different DescriptionAI19/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description author-box-with-different-description allows Cross Site Request Forgery.This issue affects Author Box Plugin With Different Description: from n/a through <= 1.3.5.
AnalizadaMedia (6.5)0.84%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application.
AnalizadaMedia (6.1)0.42%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's…
AnalizadaMedia (6.5)0.82%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server…
AnalizadaCrítica (9.6)0.41%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join,…
AnalizadaMedia (6.1)0.83%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.
ModificadaAlta (7.5)0.82%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive…
AnalizadaCrítica (9.1)0.35%—Diff Project Diff9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
AplazadaCrítica (9.3)0.40%—Silverplugins217 Different-shipping-and-billing-address-for-woocommerceAI7/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For…
AplazadaMedia (6.1)0.35%—Same BUT Different Related Posts BY TaxonomyAI7/1/202517/6/2026
The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (4.3)0.56%—Different Menu IN Different PagesAI2/5/202417/6/2026
The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax() function in all versions up to, and including, 2.3.2. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaMedia (6.3)0.68%—GradioAIAutomatic1111 Stable-diffusion-webuiAI12/4/202417/6/2026
stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on…
ModificadaAlta (7.5)0.99%—Reproducible Builds DiffoscopeFedoraproject Fedora27/2/202417/6/2026
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
ModificadaAlta (7.5)0.57%—Zanllp Stable Diffusion Webui Infinite Image Browsing22/10/202317/6/2026
The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated…
ModificadaAlta (8.8)0.78%—Ikus-soft Rdiffweb29/9/202317/6/2026
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
ModificadaMedia (6.5)0.45%—Ikus-soft Rdiffweb3/8/202317/6/2026
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
ModificadaAlta (8.2)0.57%—Jenkins Phabricator Differential2/4/202317/6/2026
Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaCrítica (9.8)0.85%—Ikus-soft Rdiffweb27/12/202217/6/2026
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
ModificadaMedia (6.5)0.65%—Ikus-soft Rdiffweb27/12/202217/6/2026
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.
ModificadaAlta (7.2)1.2%—Ikus-soft Rdiffweb27/12/202217/6/2026
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
ModificadaMedia (5.4)0.50%—Ikus-soft Rdiffweb27/12/202217/6/2026
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.
ModificadaMedia (6.1)0.50%—Ikus-soft Rdiffweb27/12/202217/6/2026
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
ModificadaCrítica (9.8)1.0%—Ikus-soft Rdiffweb27/12/202217/6/2026
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
ModificadaMedia (6.5)0.33%—Ikus-soft Rdiffweb22/12/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.