Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.54% | — | Msoft MflashAI | 15/8/2025 | 17/6/2026 | A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up… | |
| Aplazada | Crítica (9.3) | 1.9% | 💥 Exploit | FlashchatAI | 31/7/2025 | 16/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in… | |
| Analizada | Alta (7.5) | 0.52% | — | Flashmq | 29/7/2025 | 17/6/2026 | An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading to a Denial of Service (DoS). | |
| Analizada | Alta (7.5) | 0.52% | — | Flashmq | 29/7/2025 | 17/6/2026 | FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater than 0. | |
| Aplazada | Media (6.1) | 0.13% | — | YanewsflashAI | 23/7/2025 | 17/6/2026 | The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'yanewsflash/yanewsflash.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Media (5.1) | 0.22% | — | Purestorage FlasharrayAI | 16/6/2025 | 17/6/2026 | A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured. | |
| Aplazada | Media (6.1) | 0.22% | — | Easy FlashcardsAI | 14/6/2025 | 17/6/2026 | The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the 'ef_settings_submenu' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Alta (8.3) | 0.33% | — | Purestorage FlashbladeAI | 10/6/2025 | 17/6/2026 | Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service. | |
| Aplazada | Alta (8.7) | 0.38% | — | Purestorage FlasharrayAI | 10/6/2025 | 17/6/2026 | Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service. | |
| Analizada | Media (5.1) | 0.31% | — | Enilu Web-flash | 3/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible… | |
| Aplazada | Alta (7.1) | 0.22% | — | Duwasai FlashyAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duwasai Flashy allows Reflected XSS.This issue affects Flashy: from n/a through 1.2.1. | |
| Aplazada | Alta (7.1) | 0.24% | — | Lynk FlashfaderAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lynk Flashfader flashfader allows Reflected XSS.This issue affects Flashfader: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.1) | 0.13% | — | Ninos FlashcounterAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ninos FlashCounter flashcounter allows Stored XSS.This issue affects FlashCounter: from n/a through <= 1.1.8. | |
| Aplazada | Alta (8.6) | 0.19% | — | Adobe Flash Programming UtilityAI | 24/1/2025 | 17/6/2026 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Aplazada | Alta (7.1) | 0.23% | — | Flashmaniac Nature FlipbookAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature FlipBook vertical-diamond-flipbook-flash allows Reflected XSS.This issue affects Nature FlipBook: from n/a through <= 1.7. | |
| Aplazada | Media (6.5) | 0.37% | — | Foo123 TOP Flash EmbedAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foo123 Top Flash Embed top-flash-embed allows Stored XSS.This issue affects Top Flash Embed: from n/a through <= 0.3.4. | |
| Aplazada | Media (6.3) | 0.22% | — | Callerscreen Colorphone Themes CallflashAI | 6/1/2025 | 17/6/2026 | The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.android.call.color.app.activities.DialerActivity component. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Lizeipe Flash News Post ResponsiveAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlbells allows Privilege Escalation.This issue affects Flash News / Post (Responsive): from n/a through <= 4.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Litefeel Flash Show AND Hide BOXAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in litefeel Flash Show And Hide Box flash-show-and-hide-box allows Stored XSS.This issue affects Flash Show And Hide Box: from n/a through <= 1.6. | |
| Aplazada | Alta (8.5) | 0.20% | — | Openssl LibcryptoAIFlashfxpAI | 17/10/2024 | 17/6/2026 | A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has been disclosed… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Purestorage FlasharrayAI | 8/10/2024 | 17/6/2026 | A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation. | |
| Aplazada | Media (4.3) | 0.35% | — | Bplugins LLC Flash & Html5 VideoAI | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31. | |
| Aplazada | Alta (7.2) | 0.62% | — | News FlashAI | 8/8/2024 | 17/6/2026 | The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known… | |
| Modificada | Media (5.4) | 0.25% | — | Kimili Flash Embed | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Bester Kimili Flash Embed allows Stored XSS.This issue affects Kimili Flash Embed: from n/a through 2.5.3. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Purestorage FlashbladeAI | 17/7/2024 | 17/6/2026 | A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array. |