Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—FlatasticAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
AplazadaCrítica (9.8)0.56%—FlatasticAI20/8/202620/8/2026
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
AnalizadaMedia (6.6)0.49%—101arrowz Fflate22/7/202619/8/2026
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads…
AplazadaAlta (7.5)0.39%—Uxthemes FlatsomeAI13/7/202613/7/2026
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.
AplazadaAlta (7.1)0.25%—Uxthemes FlatsomeAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.
AplazadaMedia (6.5)0.34%—Uxthemes FlatsomeAI2/7/20262/7/2026
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
AplazadaMedia (4.3)0.27%—Uxthemes FlatsomeAI2/7/20262/7/2026
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
AplazadaAlta (8.4)0.42%—FlatpressAI23/6/202625/6/2026
FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers…
AplazadaAlta (7.1)0.24%—FlatonicaAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
AplazadaCrítica (9.8)0.64%—FlatnotesAI15/6/202617/6/2026
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
AnalizadaMedia (6.3)0.16%—Flatpak Xdg-desktop-portal11/4/202617/6/2026
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.
AnalizadaAlta (7.1)0.38%—Flatpak-builder9/4/202617/6/2026
flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source directory of the module. The paths from that array are resolved using g_file_resolve_relative_path() and validated to stay…
AplazadaMedia (6.5)0.22%—Themesflat-addons-for-elementorAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.2.
AnalizadaAlta (8.7)0.44%—Flatpak7/4/202624/7/2026
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This…
ModificadaCrítica (9.3)0.90%—Flatpak7/4/202624/7/2026
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and…
ModificadaMedia (6.8)0.16%—Flatpak Xdg-dbus-proxy7/4/202624/7/2026
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept…
AnalizadaAlta (8.6)0.22%—Flatassembler Flat Assembler28/3/202617/6/2026
Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return-oriented…
ModificadaAlta (8.9)0.99%—Webreflection Flatted20/3/20264/9/2026
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__"…
AplazadaMedia (5.3)0.26%—Uxthemes FlatsomeAI13/3/202617/6/2026
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.19.6.
ModificadaAlta (7.5)0.99%—Webreflection Flatted12/3/20264/9/2026
flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the…
AplazadaMedia (6.5)0.23%—Uxthemes FlatsomeAI26/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: from n/a through <= 3.20.5.
AplazadaCrítica (9.8)0.39%—Themesflat ElementorAI20/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.
AplazadaMedia (6.5)0.23%—COP UX FlatAI23/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in COP UX Flat ux-flat allows Stored XSS.This issue affects UX Flat: from n/a through <= 5.4.0.
AplazadaMedia (6.4)0.23%—Mehanoid FlatpmAI20/1/202617/6/2026
The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rank_math_description' custom field in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (4.9)0.30%—Flat Shipping Rate BY CityAI14/1/202617/6/2026
The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'cities' parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…