Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.21%—Icyleaf Ws-audio-playerAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in icyleaf WS Audio Player ws-audio-player allows Stored XSS.This issue affects WS Audio Player: from n/a through <= 1.1.8.
AplazadaAlta (7.1)0.24%—Acugis Leaflet MapsAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Ghedini AcuGIS Leaflet Maps mapfig-premium-leaflet-map-maker allows Reflected XSS.This issue affects AcuGIS Leaflet Maps: from n/a through <= 5.1.1.0.
AnalizadaMedia (5.4)0.34%—Overleaf2/9/202417/6/2026
Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the configuration for LaTeX compiles was insecure by default, requiring the administrator to enable the security features via a…
AnalizadaMedia (5.3)0.48%—Overleaf2/9/202417/6/2026
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary language parameter in client spelling requests to be passed to the `aspell` executable running on the server. This causes…
ModificadaMedia (5.4)0.26%—Mapsmarker Leaflet Maps Marker21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MapsMarker.Com e.U. Leaflet Maps Marker allows Stored XSS.This issue affects Leaflet Maps Marker: from n/a through 3.12.9.
AplazadaMedia (6.4)0.43%—Mapsmarker Leaflet Maps MarkerAI2/5/202417/6/2026
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mapsmarker' shortcode in all versions up to, and including, 3.12.8 due to insufficient input sanitization and output escaping on user supplied attributes such as…
ModificadaAlta (7.5)0.59%—Nanoleaf Lightstrip Firmware31/10/202317/6/2026
An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.
ModificadaMedia (5.4)0.49%—Bozdoz Leaflet MAP20/10/202317/6/2026
The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web…
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaMedia (6.1)0.38%—Hupe13 Extensions FOR Leaflet MAP17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in hupe13 Extensions for Leaflet Map plugin <= 3.4.1 versions.
ModificadaAlta (7.5)0.97%—Codecentric Spring Boot AdminThymeleaf14/7/202317/6/2026
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to…
ModificadaMedia (6.1)0.50%—Broadleafcommerce Broadleaf Commerce21/6/202317/6/2026
Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
ModificadaCrítica (9.8)1.2%—Nanoleaf Firmware27/4/20239/7/2026
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
ModificadaCrítica (9.8)1.9%—Nanoleaf Desktop18/4/20239/7/2026
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
ModificadaMedia (5.4)0.56%—Mapsmarker Leaflet Maps Marker6/2/202317/6/2026
The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaAlta (7.2)1.3%—Mapsmarker Leaflet Maps Marker29/8/202217/6/2026
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.
ModificadaCrítica (9.8)4.0%—Thymeleaf9/11/202117/6/2026
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
ModificadaMedia (6.1)0.71%—Vapor Leafkit9/8/202117/6/2026
Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as variables. If an attacker managed to…
ModificadaMedia (6.5)0.56%—Leaflet MAP Project Leaflet MAP9/8/202117/6/2026
The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being…
ModificadaMedia (5.4)0.62%—Bozdoz Leaflet MAP2/8/202117/6/2026
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues
ModificadaMedia (6.1)0.77%—Broadleafcommerce Broadleaf Commerce29/10/202017/6/2026
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
ModificadaAlta (8.8)1.7%—Leaftecnologia Leaf Admin15/8/201917/6/2026
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
ModificadaMedia (6.5)1.1%—IBM Tealeaf Customer Experience27/3/201817/6/2026
The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.
ModificadaMedia (6.5)1.8%—IBM Tealeaf Customer Experience26/1/201817/6/2026
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 124757.
ModificadaCrítica (9.8)1.6%—IBM Tealeaf Customer Experience26/1/201817/6/2026
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 123740.