Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 61 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.29%—Nvidia Jetpack Software Development KIT8/7/202017/6/2026
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.
ModificadaMedia (6.1)0.95%—Automattic Jetpack28/8/201917/6/2026
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaMedia (6.1)0.96%—Automattic Jetpack12/1/201817/6/2026
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
ModificadaMedia (6.1)0.95%—Automattic Jetpack12/1/201817/6/2026
The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
ModificadaMedia (5.8)2.3%—Automattic Jetpack22/4/201417/6/2026
The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.2, 2.6.x before 2.6.3, 2.7.x before 2.7.2, 2.8.x before 2.8.2, and 2.9.x before 2.9.3 for WordPress does not properly restrict access to the XML-RPC service,…
ModificadaAlta (7.5)2.1%—Automattic Jetpack2/12/201116/6/2026
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.