Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Wpdeveloper EmbedpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
AplazadaCrítica (9.1)0.50%—Embedded-solutions FreemodbusAI5/8/202626/8/2026
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.
AplazadaMedia (5.8)0.33%—Wpdeveloper EmbedpressAI4/8/202626/8/2026
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind…
AplazadaCrítica (9.8)0.84%—Elearningfreak Insert OR Embed Articulate ContentAI3/8/202626/8/2026
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers…
AplazadaCrítica (9.8)3.0%—Advanced Responsive Video EmbedderAI29/7/202630/7/2026
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs…
AplazadaAlta (7.2)0.27%—3dflipbook PDF Viewer AND EmbedderAI27/7/202627/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
AplazadaMedia (5.3)0.31%—Fediverse EmbedsAI9/7/20269/7/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and…
AplazadaMedia (5.3)0.31%—Fediverse EmbedsAI9/7/20269/7/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body.…
AplazadaAlta (7.1)0.41%—Epiph Embed PrivacyAI29/6/202629/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
AplazadaAlta (7.5)0.39%—Wpdeveloper EmbedpressAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Pendiente de análisisAlta (7)0.08%—Moxa Embedded Linux FirmwareAI12/6/202617/6/2026
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714.…
AplazadaMedia (5.3)0.40%—Fediverse EmbedsAI11/6/202617/6/2026
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the attacker-supplied…
AplazadaAlta (7.5)0.41%—Fediverse EmbedsAI11/6/202617/6/2026
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($url) without enforcing…
Pendiente de análisisAlta (8.4)0.08%—Lenovo Thinkpad Embedded Controller FirmwareAI10/6/202630/9/2026
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.
AnalizadaCrítica (9.3)6.4%⚠ Explotación activaCheckpoint Gaia OSCheckpoint Gaia Embedded8/6/20264/8/2026
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
AplazadaMedia (6.4)0.42%—Wpdeveloper EmbedpressAI6/6/202623/7/2026
The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (4.3)0.41%—Wp-pdf PDF EmbedderAI28/5/202622/8/2026
The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when…
AplazadaMedia (6.4)0.32%—Responsive Video EmbedderAI27/5/202617/6/2026
The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'list') in the video_shortcode()…
AplazadaMedia (4.3)0.19%—Zawgyi EmbedAI12/5/202617/6/2026
The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the zawgyi_adminpage function. This makes it possible for unauthenticated attackers to update the plugin's zawgyi_forceCSS setting by…
AplazadaMedia (6.4)0.35%—Social Post EmbedAI28/4/202617/6/2026
The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on the user-supplied URL. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.23%—Bplugins 3D Viewer Embed 3D ModelsAI15/4/202617/6/2026
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
AplazadaMedia (5.3)0.89%—3D Flipbook PDF EmbedderAI15/4/202617/6/2026
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to…
AplazadaMedia (4.3)0.27%—Embedplus Youtube Embed PlusAI8/4/202624/7/2026
Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.
AplazadaMedia (6.4)0.41%—WP Games EmbedAI21/3/202617/6/2026
The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1beta. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'width', 'height', 'src', 'title', 'description',…
AplazadaMedia (6.4)0.20%—Davidartiss Code EmbedAI18/3/202617/6/2026
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2.5.1. This is due to the plugin's sanitization function `sec_check_post_fields()` only running on the `save_post` hook, while WordPress allows custom fields to be added…