Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper EmbedpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Embedded-solutions FreemodbusAI | 5/8/2026 | 26/8/2026 | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. | |
| Aplazada | Media (5.8) | 0.33% | — | Wpdeveloper EmbedpressAI | 4/8/2026 | 26/8/2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Elearningfreak Insert OR Embed Articulate ContentAI | 3/8/2026 | 26/8/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers… | |
| Aplazada | Crítica (9.8) | 3.0% | — | Advanced Responsive Video EmbedderAI | 29/7/2026 | 30/7/2026 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs… | |
| Aplazada | Alta (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Fediverse EmbedsAI | 9/7/2026 | 9/7/2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and… | |
| Aplazada | Media (5.3) | 0.31% | — | Fediverse EmbedsAI | 9/7/2026 | 9/7/2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body.… | |
| Aplazada | Alta (7.1) | 0.41% | — | Epiph Embed PrivacyAI | 29/6/2026 | 29/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpdeveloper EmbedpressAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. | |
| Pendiente de análisis | Alta (7) | 0.08% | — | Moxa Embedded Linux FirmwareAI | 12/6/2026 | 17/6/2026 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714.… | |
| Aplazada | Media (5.3) | 0.40% | — | Fediverse EmbedsAI | 11/6/2026 | 17/6/2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the attacker-supplied… | |
| Aplazada | Alta (7.5) | 0.41% | — | Fediverse EmbedsAI | 11/6/2026 | 17/6/2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($url) without enforcing… | |
| Pendiente de análisis | Alta (8.4) | 0.08% | — | Lenovo Thinkpad Embedded Controller FirmwareAI | 10/6/2026 | 30/9/2026 | During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. | |
| Analizada | Crítica (9.3) | 6.4% | ⚠ Explotación activa | Checkpoint Gaia OSCheckpoint Gaia Embedded | 8/6/2026 | 4/8/2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper EmbedpressAI | 6/6/2026 | 23/7/2026 | The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (4.3) | 0.41% | — | Wp-pdf PDF EmbedderAI | 28/5/2026 | 22/8/2026 | The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when… | |
| Aplazada | Media (6.4) | 0.32% | — | Responsive Video EmbedderAI | 27/5/2026 | 17/6/2026 | The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'list') in the video_shortcode()… | |
| Aplazada | Media (4.3) | 0.19% | — | Zawgyi EmbedAI | 12/5/2026 | 17/6/2026 | The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the zawgyi_adminpage function. This makes it possible for unauthenticated attackers to update the plugin's zawgyi_forceCSS setting by… | |
| Aplazada | Media (6.4) | 0.35% | — | Social Post EmbedAI | 28/4/2026 | 17/6/2026 | The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on the user-supplied URL. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.23% | — | Bplugins 3D Viewer Embed 3D ModelsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5. | |
| Aplazada | Media (5.3) | 0.89% | — | 3D Flipbook PDF EmbedderAI | 15/4/2026 | 17/6/2026 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.27% | — | Embedplus Youtube Embed PlusAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4. | |
| Aplazada | Media (6.4) | 0.41% | — | WP Games EmbedAI | 21/3/2026 | 17/6/2026 | The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1beta. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'width', 'height', 'src', 'title', 'description',… | |
| Aplazada | Media (6.4) | 0.20% | — | Davidartiss Code EmbedAI | 18/3/2026 | 17/6/2026 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2.5.1. This is due to the plugin's sanitization function `sec_check_post_fields()` only running on the `save_post` hook, while WordPress allows custom fields to be added… |