Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

118 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.4)0.34%—Team Members Multi Language Supported Team PluginAI30/6/202630/6/2026
The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
Pendiente de análisisAlta (8.5)0.19%—Amazon Language ServersAI23/6/202623/6/2026
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users…
Pendiente de análisisAlta (8.5)0.23%—Amazon Language ServersAI23/6/202623/6/2026
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the…
AnalizadaAlta (8.7)0.50%—Angular Language Service22/6/202626/6/2026
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all…
AnalizadaAlta (8.7)0.24%—Angular Language Service22/6/202626/6/2026
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk.path directly from workspace configurations (.vscode/settings.json)…
AplazadaAlta (8.8)0.42%—Falang MultilanguageAI17/6/202617/6/2026
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
AnalizadaAlta (8.4)0.24%—Vercel Turborepo Language Server Protocol15/5/202617/6/2026
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious…
AplazadaMedia (6.4)0.43%—Quran Live MultilanguageAI22/4/202617/6/2026
The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lang' shortcode attributes in all versions up to, and including, 1.0.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The quran_live_render()…
AplazadaMedia (5.9)0.17%—Pascal Birchler Preferred LanguagesAI6/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Languages: from n/a through 2.2.2.
AplazadaMedia (5.5)0.36%—User Language SwitchAI14/2/202617/6/2026
The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…
AplazadaMedia (4.4)0.25%—User Language SwitchAI14/2/202617/6/2026
The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.29%—Bestwebsoft MultilanguageAI23/1/202617/6/2026
Missing Authorization vulnerability in bestwebsoft Multilanguage by BestWebSoft multilanguage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multilanguage by BestWebSoft: from n/a through <= 1.5.2.
AnalizadaAlta (8.8)0.71%—Microsoft Azure Language18/12/202517/6/2026
Custom Question Answering Elevation of Privilege Vulnerability
AplazadaAlta (8.8)0.38%—Sbouey Falang MultilanguageAI6/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage: from n/a through <= 1.3.65.
AplazadaMedia (4.4)0.23%—Bootstrap Multi Language Responsive PortfolioAI4/11/202517/6/2026
The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaAlta (8.8)0.35%—Wikimedia Mediawiki - Languageselector ExtensionAI20/10/202517/6/2026
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39.
AplazadaMedia (6.4)0.19%—A Simple Multilanguage PluginAI3/10/202517/6/2026
The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'asmp-switcher' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.5)0.21%—Michel - Xiligroup DEV Xili-languageAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language xili-language allows DOM-Based XSS.This issue affects xili-language: from n/a through <= 2.21.3.
AplazadaAlta (7.1)0.23%—Webilop User Language SwitchAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilop User Language Switch user-language-switch allows Reflected XSS.This issue affects User Language Switch: from n/a through <= 1.6.10.
ModificadaMedia (6.1)0.31%—Languagesloth THE Language Sloth1/8/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description text field.
AnalizadaCrítica (9.8)0.41%—Gitlab Language Server28/7/202517/6/2026
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
AplazadaAlta (7.5)0.40%—Augustinfotech Multi-language Responsive Contact FormAI16/7/202517/6/2026
Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form responsive-contact-form allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Multi-language Responsive Contact Form: from n/a through <= 2.8.
AplazadaMedia (4.3)0.14%—Sbouey Falang MultilanguageAI19/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage falang allows Cross Site Request Forgery.This issue affects Falang multilanguage: from n/a through <= 1.3.61.
AplazadaMedia (5.9)0.27%—Karim42 Quran Multilanguage Text & AudioAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karim42 Quran multilanguage Text & Audio quran-text-multilanguage allows Stored XSS.This issue affects Quran multilanguage Text & Audio: from n/a through <= 2.3.23.
AplazadaAlta (7.1)0.15%—Alexander Rauscha MlanguageAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage mlanguage allows Stored XSS.This issue affects mLanguage: from n/a through <= 1.6.1.