Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.56% | — | Filamentphp FilamentAI | 7/11/2024 | 17/6/2026 | Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driver to something production-ready like `s3` when deploying their app, without… | |
| Aplazada | Media (5.3) | 0.40% | — | Lara-zeus Dynamic DashboardAILara-zeus Filament DashboardAIApache ArtemisAI | 7/10/2024 | 17/6/2026 | Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS… | |
| Analizada | Media (6.1) | 0.42% | — | Filamentphp Filament | 27/9/2024 | 17/6/2026 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are… | |
| Analizada | Alta (7.5) | 0.57% | — | Pxlrbt Filament Excel | 12/8/2024 | 17/6/2026 | Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3. | |
| Aplazada | Alta (7.6) | 0.52% | — | Flamescorpion Auto Affiliate LinksAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1. | |
| Aplazada | Media (6.5) | 0.31% | — | WP CalameoAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calameo WP Calameo allows Stored XSS.This issue affects WP Calameo: from n/a through 2.1.7. | |
| Modificada | Media (4.3) | 0.53% | — | Flamescorpion Auto Affiliate Links | 13/3/2024 | 17/6/2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to… | |
| Modificada | Media (6.1) | 0.21% | — | Flamescorpion Auto Affiliate Links | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4. | |
| Modificada | Crítica (9.1) | 1.1% | — | Blamer Project Blamer | 19/9/2023 | 17/6/2026 | Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX… | |
| Modificada | Alta (8.8) | 0.26% | — | Flamescorpion Auto Affiliate Links | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Flamescorpion Auto Affiliate Links | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions. | |
| Modificada | Media (6.1) | 0.49% | — | Flame.js Project Flame.js | 5/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in flame.js. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The… | |
| Modificada | Crítica (9.8) | 1.3% | — | Gitblame Project Gitblame | 2/8/2022 | 17/6/2026 | This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. | |
| Modificada | Crítica (9.8) | 1.1% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | |
| Modificada | Crítica (9.8) | 0.99% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | |
| Modificada | Crítica (9.8) | 4.3% | — | Blamer Project Blamer | 20/3/2020 | 17/6/2026 | Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker. | |
| Modificada | Crítica (9.8) | 2.4% | — | Blamer Project Blamer | 11/3/2020 | 17/6/2026 | Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer. | |
| Modificada | Crítica (9.8) | 5.0% | — | Flamecms Project Flamecms | 14/9/2019 | 17/6/2026 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | |
| Modificada | Media (5.5) | 0.73% | — | Lame Project Lame | 6/10/2017 | 17/6/2026 | LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412. | |
| Modificada | Media (5.5) | 0.90% | — | Lame Project Lame | 6/10/2017 | 17/6/2026 | LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410. | |
| Modificada | Alta (7.8) | 1.1% | — | Lame Project Lame | 5/10/2017 | 17/6/2026 | LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call. | |
| Modificada | Media (5.5) | 0.84% | — | Lame Project Lame | 5/10/2017 | 17/6/2026 | LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c. | |
| Modificada | Alta (7.5) | 1.7% | — | Lame Project Lame | 28/8/2017 | 17/6/2026 | NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument. | |
| Modificada | Crítica (9.8) | 2.5% | — | Lame Project Lame | 28/7/2017 | 17/6/2026 | There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file. | |
| Modificada | Media (5.5) | 4.0% | 💥 Exploit | Lame Project Lame | 27/7/2017 | 17/6/2026 | The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file. |