Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.34% | — | Rankmath Rank Math SEOAI | 2/9/2026 | 3/9/2026 | The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts. | |
| Aplazada | Media (4.9) | 0.33% | — | Rankmath Rank Math SEOAI | 29/8/2026 | 31/8/2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators. | |
| Aplazada | Alta (7.2) | 0.78% | — | Rankmath Rank Math SEOAI | 28/8/2026 | 28/8/2026 | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Rankmath Rank Math SEOAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | |
| Aplazada | Media (6.3) | 0.36% | — | MathliveAI | 29/7/2026 | 30/7/2026 | MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEscape, scanText, and text-mode output in src/formats/atom-to-math-ml.ts, and through convertLatexToMarkup,… | |
| Analizada | Crítica (9.8) | 2.0% | — | Shivammathur Setup PHP | 17/7/2026 | 18/8/2026 | setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and composer.json through… | |
| Aplazada | Media (6.5) | 0.30% | — | Rankmath Rank Math SEOAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions. | |
| Aplazada | Media (5.3) | 0.41% | — | Rankmath Rank Math SEOAI | 29/5/2026 | 21/7/2026 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin… | |
| Aplazada | Media (5.3) | 0.38% | — | MathesarAIPostgresqlAI | 15/5/2026 | 17/6/2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list, tables.metadata.list, explorations.list, and forms.list accept a database_id without verifying that the requesting user was a collaborator on that database. An… | |
| Aplazada | Media (5.3) | 0.38% | — | MathesarAI | 15/5/2026 | 17/6/2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete operate on an exploration_id without verifying that the requesting user was a collaborator on the exploration’s database. An… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Crítica (9.8) | 0.67% | — | Mauriciopoppe Math-codegen | 8/5/2026 | 17/6/2026 | math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization. This allows an attacker to execute arbitrary system commands when user-controlled input reaches the parser. Any… | |
| Modificada | Alta (8.8) | 0.80% | — | Mathjs | 7/5/2026 | 15/7/2026 | Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0. | |
| Modificada | Alta (8.8) | 0.76% | — | Mathjs | 24/4/2026 | 15/7/2026 | Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser.… | |
| Aplazada | Media (6.4) | 0.33% | — | WM JqmathAI | 15/4/2026 | 17/6/2026 | The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of the [jqmath] shortcode in all versions up to and including 1.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The generate_jqMathFormula()… | |
| Aplazada | Media (4.3) | 0.26% | — | Rankmath Rank Math SEO PROAI | 6/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95. | |
| Analizada | Media (5.5) | 0.54% | — | Vishalmathur Cloudclassroom-php-project | 6/2/2026 | 17/6/2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql injection. The attack is possible to be… | |
| Analizada | Alta (7.5) | 0.41% | — | Script3 Soroban-fixed-point-math | 27/1/2026 | 17/6/2026 | soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the… | |
| Analizada | Crítica (9.8) | 0.30% | — | Vishalmathur Institute-of-current-students | 20/11/2025 | 17/6/2026 | Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in SQL queries. | |
| Aplazada | Media (4.8) | 0.11% | — | Intel Oneapi Math Kernel LibraryAI | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Aplazada | Media (4.3) | 0.22% | — | Rankmath Rank Math SEOAI | 31/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1. | |
| Aplazada | Baja (3.8) | 0.24% | — | Rankmath Rank Math SEOAI | 31/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1. | |
| Aplazada | Media (6.1) | 0.23% | — | Byaidu PdfmathtranslateAI | 30/10/2025 | 17/6/2026 | An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or to bypass security… | |
| Aplazada | Media (6.5) | 0.41% | — | Sagemath INC CocalcAI | 16/10/2025 | 17/6/2026 | An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
| Analizada | Crítica (9.8) | 0.83% | — | Vishalmathur Online Artwork AND Fine Arts Project | 20/8/2025 | 17/6/2026 | A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution. |