Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | FlatasticAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | FlatasticAI | 20/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | |
| Analizada | Media (6.6) | 0.49% | — | 101arrowz Fflate | 22/7/2026 | 19/8/2026 | fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads… | |
| Aplazada | Alta (7.5) | 0.39% | — | Uxthemes FlatsomeAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Uxthemes FlatsomeAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5. | |
| Aplazada | Media (6.5) | 0.34% | — | Uxthemes FlatsomeAI | 2/7/2026 | 2/7/2026 | Contributor Broken Access Control in Flatsome <= 3.20.5 versions. | |
| Aplazada | Media (4.3) | 0.27% | — | Uxthemes FlatsomeAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Flatsome <= 3.20.5 versions. | |
| Aplazada | Alta (8.4) | 0.42% | — | FlatpressAI | 23/6/2026 | 25/6/2026 | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers… | |
| Aplazada | Alta (7.1) | 0.24% | — | FlatonicaAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions. | |
| Aplazada | Crítica (9.8) | 0.64% | — | FlatnotesAI | 15/6/2026 | 17/6/2026 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file. | |
| Analizada | Media (6.3) | 0.16% | — | Flatpak Xdg-desktop-portal | 11/4/2026 | 17/6/2026 | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash. | |
| Analizada | Alta (7.1) | 0.38% | — | Flatpak-builder | 9/4/2026 | 17/6/2026 | flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source directory of the module. The paths from that array are resolved using g_file_resolve_relative_path() and validated to stay… | |
| Aplazada | Media (6.5) | 0.22% | — | Themesflat-addons-for-elementorAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.2. | |
| Analizada | Alta (8.7) | 0.44% | — | Flatpak | 7/4/2026 | 24/7/2026 | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This… | |
| Modificada | Crítica (9.3) | 0.90% | — | Flatpak | 7/4/2026 | 24/7/2026 | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and… | |
| Modificada | Media (6.8) | 0.16% | — | Flatpak Xdg-dbus-proxy | 7/4/2026 | 24/7/2026 | xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept… | |
| Analizada | Alta (8.6) | 0.22% | — | Flatassembler Flat Assembler | 28/3/2026 | 17/6/2026 | Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return-oriented… | |
| Modificada | Alta (8.9) | 0.99% | — | Webreflection Flatted | 20/3/2026 | 4/9/2026 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__"… | |
| Aplazada | Media (5.3) | 0.26% | — | Uxthemes FlatsomeAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.19.6. | |
| Modificada | Alta (7.5) | 0.99% | — | Webreflection Flatted | 12/3/2026 | 4/9/2026 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the… | |
| Aplazada | Media (6.5) | 0.23% | — | Uxthemes FlatsomeAI | 26/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: from n/a through <= 3.20.5. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Themesflat ElementorAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.23% | — | COP UX FlatAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in COP UX Flat ux-flat allows Stored XSS.This issue affects UX Flat: from n/a through <= 5.4.0. | |
| Aplazada | Media (6.4) | 0.23% | — | Mehanoid FlatpmAI | 20/1/2026 | 17/6/2026 | The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rank_math_description' custom field in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.9) | 0.30% | — | Flat Shipping Rate BY CityAI | 14/1/2026 | 17/6/2026 | The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'cities' parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… |