Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (2)0.36%—OpenvpnAIARM MbedtlsAI14/8/20261/9/2026
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
AplazadaMedia (6.8)0.43%💥 PoCEmbed Google Photos AlbumAI14/8/202626/8/2026
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the…
Pendiente de análisisAlta (8.4)0.18%—Op-tee OSAIMbedtlsAINXP Se050AI10/8/202624/9/2026
OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an input length…
AplazadaMedia (6.5)0.29%—Davidartiss Code EmbedAI7/8/20269/9/2026
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output…
AplazadaAlta (7.1)0.25%—Wpdeveloper EmbedpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
AplazadaCrítica (9.1)0.50%—Embedded-solutions FreemodbusAI5/8/202626/8/2026
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.
AplazadaMedia (5.8)0.33%—Wpdeveloper EmbedpressAI4/8/202626/8/2026
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind…
AplazadaCrítica (9.8)0.84%—Elearningfreak Insert OR Embed Articulate ContentAI3/8/202626/8/2026
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers…
AplazadaCrítica (9.8)3.0%💥 ExploitAdvanced Responsive Video EmbedderAI29/7/202630/7/2026
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs…
AplazadaAlta (7.2)0.27%—3dflipbook PDF Viewer AND EmbedderAI27/7/202627/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
AplazadaMedia (5.3)0.31%—Fediverse EmbedsAI9/7/20269/7/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and…
AplazadaMedia (5.3)0.31%—Fediverse EmbedsAI9/7/20269/7/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body.…
AplazadaAlta (7.1)0.41%—Epiph Embed PrivacyAI29/6/202629/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
AplazadaAlta (7.5)0.39%—Wpdeveloper EmbedpressAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Pendiente de análisisAlta (7)0.08%—Moxa Embedded Linux FirmwareAI12/6/202617/6/2026
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714.…
AplazadaMedia (5.3)0.40%—Fediverse EmbedsAI11/6/202617/6/2026
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the attacker-supplied…
AplazadaAlta (7.5)0.41%—Fediverse EmbedsAI11/6/202617/6/2026
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($url) without enforcing…
Pendiente de análisisAlta (8.4)0.08%—Lenovo Thinkpad Embedded Controller FirmwareAI10/6/20267/10/2026
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.
AnalizadaCrítica (9.3)6.4%⚠ Explotación activa💥 ExploitCheckpoint Gaia OSCheckpoint Gaia Embedded8/6/20264/8/2026
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
AplazadaMedia (6.4)0.42%—Wpdeveloper EmbedpressAI6/6/202623/7/2026
The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (4.3)0.41%—Wp-pdf PDF EmbedderAI28/5/202622/8/2026
The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when…
AplazadaMedia (6.4)0.32%—Responsive Video EmbedderAI27/5/202617/6/2026
The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'list') in the video_shortcode()…
AplazadaMedia (4.3)0.19%—Zawgyi EmbedAI12/5/202617/6/2026
The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the zawgyi_adminpage function. This makes it possible for unauthenticated attackers to update the plugin's zawgyi_forceCSS setting by…
AplazadaMedia (6.4)0.35%—Social Post EmbedAI28/4/202617/6/2026
The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on the user-supplied URL. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.23%—Bplugins 3D Viewer Embed 3D ModelsAI15/4/202617/6/2026
Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.
Orbitaley — Vulnerabilidades