Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.16% | — | Loopus WP Ultimate Tours BuilderAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder WP_UltimateToursBuilder allows Cross Site Request Forgery.This issue affects WP Ultimate Tours Builder: from n/a through <= 1.055. | |
| Aplazada | Media (5.3) | 0.50% | — | Viralloops Viral Loops WP IntegrationAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Retrieve Embedded Sensitive Data.This issue affects Viral Loops WP Integration: from n/a through <= 3.4.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | Ulrich Sossou THE LoopsAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ulrich Sossou The Loops the-loops allows Reflected XSS.This issue affects The Loops: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.1) | 0.30% | — | Tangible Loops AND LogicAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Reflected XSS.This issue affects Loops & Logic: from n/a through <= 4.1.4. | |
| Analizada | Crítica (9.8) | 0.88% | — | Closed-loop Cless Server | 19/9/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint. | |
| Aplazada | Crítica (10) | 0.92% | — | Robinweser Fast-loopsAI | 1/7/2024 | 17/6/2026 | robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Modificada | Media (6.1) | 0.29% | — | Loopus WP Visitors Tracker | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3. | |
| Aplazada | Media (6.5) | 0.31% | — | Kailey Lampert Mini LoopsAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Mini Loops allows Stored XSS.This issue affects Mini Loops: from n/a through 1.4.1. | |
| Aplazada | Alta (7.1) | 0.35% | — | Loopus WP Cost Estimation AND Payment Forms BuilderAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Loopus WP Cost Estimation & Payment Forms Builder allows Reflected XSS.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.75. | |
| Aplazada | Media (6.5) | 0.44% | — | Loopus WP Cost Estimation & Payment Forms BuilderAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.76. | |
| Aplazada | Alta (8.5) | 0.49% | — | Loopus WP Cost Estimation AND Payment Forms BuilderAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.75. | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Crítica (10) | 0.62% | — | Linuxfoundation Loopback-connector-postgresql | 12/8/2022 | 17/6/2026 | Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the… | |
| Modificada | Media (6) | 0.33% | — | V4l2loopback Project V4l2loopback | 4/8/2022 | 17/6/2026 | Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers in a row). | |
| Modificada | Media (5.4) | 1.2% | — | Rainloop Webmail | 28/7/2022 | 17/6/2026 | The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message. | |
| Modificada | Alta (8.1) | 1.0% | — | Tencent Gameloop | 6/6/2021 | 17/6/2026 | Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a download URL with one pointing to an arbitrary Windows executable. Because the only integrity check would… | |
| Modificada | Alta (7.5) | 1.4% | — | Loopring | 3/1/2021 | 17/6/2026 | The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation. | |
| Modificada | Crítica (9.8) | 1.5% | — | IBM Loopback | 21/12/2020 | 17/6/2026 | Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or possibly execute code. IBM X-Force ID: 192706. | |
| Modificada | Crítica (9.8) | 3.0% | — | IBM Strongloop Nginx Controller | 2/4/2020 | 17/6/2026 | strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function. | |
| Modificada | Media (6.1) | 0.87% | — | Rainloop Webmail | 20/3/2020 | 17/6/2026 | RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header. | |
| Modificada | Alta (8.8) | 2.1% | — | Icon Loopchain | 28/6/2019 | 17/6/2026 | In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment (aka injection in the DEFAULT_SCORE_HOST environment variable). | |
| Modificada | Media (4.3) | 0.74% | — | Bloop Airmail | 21/8/2018 | 17/6/2026 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the default URL handler. A navigation request is processed by the default URL handler only if the currentEvent is… | |
| Modificada | Media (5.3) | 0.88% | — | Bloop Airmail 3 | 21/8/2018 | 17/6/2026 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from HTMLIFrameElements are blacklisted. However, other sub-classes of HTMLFrameOwnerElements are not forbidden by the policy.… | |
| Modificada | Media (5.3) | 0.88% | — | Bloop Airmail 3 | 21/8/2018 | 17/6/2026 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" command with the "attachment_" prefix designate attachment parameters. If the value of an attachment… | |
| Modificada | Alta (7.5) | 2.0% | — | Looppake Project Looppake | 7/6/2018 | 17/6/2026 | looppake is a simple http server. looppake is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. |