Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)0.56%—Filamentphp FilamentAI7/11/202417/6/2026
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driver to something production-ready like `s3` when deploying their app, without…
AplazadaMedia (5.3)0.40%—Lara-zeus Dynamic DashboardAILara-zeus Filament DashboardAIApache ArtemisAI7/10/202417/6/2026
Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS…
AnalizadaMedia (6.1)0.42%—Filamentphp Filament27/9/202417/6/2026
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are…
AnalizadaAlta (7.5)0.57%—Pxlrbt Filament Excel12/8/202417/6/2026
Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
AplazadaAlta (7.6)0.52%—Flamescorpion Auto Affiliate LinksAI6/5/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.
AplazadaMedia (6.5)0.31%—WP CalameoAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calameo WP Calameo allows Stored XSS.This issue affects WP Calameo: from n/a through 2.1.7.
ModificadaMedia (4.3)0.53%—Flamescorpion Auto Affiliate Links13/3/202417/6/2026
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to…
ModificadaMedia (6.1)0.21%—Flamescorpion Auto Affiliate Links13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4.
ModificadaCrítica (9.1)1.1%—Blamer Project Blamer19/9/202317/6/2026
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX…
ModificadaAlta (8.8)0.26%—Flamescorpion Auto Affiliate Links20/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions.
ModificadaAlta (8.8)0.25%—Flamescorpion Auto Affiliate Links13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.
ModificadaMedia (6.1)0.49%—Flame.js Project Flame.js5/3/202317/6/2026
A vulnerability classified as problematic has been found in flame.js. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The…
ModificadaCrítica (9.8)1.3%—Gitblame Project Gitblame2/8/202217/6/2026
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
ModificadaCrítica (9.8)1.1%—Flamecms Project Flamecms30/9/202117/6/2026
FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
ModificadaCrítica (9.8)0.99%—Flamecms Project Flamecms30/9/202117/6/2026
FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
ModificadaCrítica (9.8)4.3%—Blamer Project Blamer20/3/202017/6/2026
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
ModificadaCrítica (9.8)2.4%—Blamer Project Blamer11/3/202017/6/2026
Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.
ModificadaCrítica (9.8)5.0%—Flamecms Project Flamecms14/9/201917/6/2026
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
ModificadaMedia (5.5)0.73%—Lame Project Lame6/10/201717/6/2026
LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412.
ModificadaMedia (5.5)0.90%—Lame Project Lame6/10/201717/6/2026
LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410.
ModificadaAlta (7.8)1.1%—Lame Project Lame5/10/201717/6/2026
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.
ModificadaMedia (5.5)0.84%—Lame Project Lame5/10/201717/6/2026
LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c.
ModificadaAlta (7.5)1.7%—Lame Project Lame28/8/201717/6/2026
NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument.
ModificadaCrítica (9.8)2.5%—Lame Project Lame28/7/201717/6/2026
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
ModificadaMedia (5.5)4.0%💥 ExploitLame Project Lame27/7/201717/6/2026
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.
Orbitaley — Vulnerabilidades