Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
181 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.62% | — | Mahara | 22/8/2025 | 17/6/2026 | Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code execution when being processed. | |
| Modificada | Media (5.4) | 0.26% | — | Beakon Learning Management System Sharable Content Object Reference Model | 17/7/2025 | 5/7/2026 | Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter | |
| Analizada | Crítica (9.8) | 0.70% | — | Beakon Learning Management System Sharable Content Object Reference Model | 23/6/2025 | 17/6/2026 | SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file | |
| Aplazada | Alta (8.1) | 0.58% | — | Thembay HaraAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local File Inclusion.This issue affects Hara: from n/a through <= 1.2.10. | |
| Aplazada | Media (4.3) | 0.39% | — | Sharaz Shahid Simple Sticky ADD TO Cart FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Sharaz Shahid Simple Sticky Add To Cart For WooCommerce sticky-add-to-cart-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Sticky Add To Cart For WooCommerce: from n/a through <= 1.4.9. | |
| Aplazada | Alta (7.5) | 0.37% | — | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS ApplicationAI | 4/3/2025 | 17/6/2026 | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history,… | |
| Aplazada | Alta (7.1) | 0.30% | — | Magent Vampire Character ManagerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magent Vampire Character Manager vampire-character allows Reflected XSS.This issue affects Vampire Character Manager: from n/a through <= 2.13. | |
| Analizada | Media (6.1) | 0.38% | — | Syedfakharabbas Backlink Monitoring Manager | 9/1/2025 | 17/6/2026 | The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.5) | 0.35% | — | Bharatkambariya Donation Block FOR PaypalAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bharat Kambariya Donation Block For PayPal donations-block allows Stored XSS.This issue affects Donation Block For PayPal: from n/a through <= 2.2.0. | |
| Analizada | Media (6.8) | 0.45% | — | Bharatkambariya Donation Block FOR Paypal | 30/7/2024 | 17/6/2026 | The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability | |
| Aplazada | Media (6.5) | 0.31% | — | Sharabindu QR Code ComposerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sharabindu QR Code Composer allows Stored XSS.This issue affects QR Code Composer: from n/a through 2.0.3. | |
| Modificada | Media (4.8) | 0.40% | — | Benaceur-php Restrict Usernames Emails Characters | 29/1/2024 | 17/6/2026 | The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Crítica (9.8) | 0.81% | — | Mahara | 6/11/2022 | 17/6/2026 | Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript. | |
| Modificada | Alta (7.5) | 0.65% | — | Mahara | 6/11/2022 | 17/6/2026 | In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions. | |
| Modificada | Alta (7.8) | 0.40% | — | Adobe Character Animator | 15/7/2022 | 17/6/2026 | Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the… | |
| Modificada | Alta (7.8) | 0.48% | — | Adobe Character Animator | 15/7/2022 | 17/6/2026 | Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.5) | 1.1% | — | Mahara | 20/6/2022 | 17/6/2026 | In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check. | |
| Modificada | Media (6.1) | 5.1% | — | Angtech Haraj | 16/6/2022 | 17/6/2026 | Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form. | |
| Modificada | Media (5.4) | 0.85% | — | Angtech Haraj | 16/6/2022 | 17/6/2026 | Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component. | |
| Modificada | Media (5.4) | 1.2% | — | Angtech Haraj | 16/6/2022 | 17/6/2026 | A cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | |
| Modificada | Media (5.4) | 1.2% | — | Angtech Haraj | 16/6/2022 | 17/6/2026 | A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | |
| Modificada | Alta (7.8) | 2.9% | — | Adobe Character Animator | 12/5/2022 | 17/6/2026 | Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file. | |
| Modificada | Alta (7.5) | 1.0% | — | Mahara | 28/4/2022 | 17/6/2026 | In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of). | |
| Modificada | Media (5.4) | 0.52% | — | Mahara | 28/4/2022 | 17/6/2026 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action. | |
| Modificada | Alta (8.8) | 0.46% | — | Mahara | 28/4/2022 | 17/6/2026 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable. |