Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2) | 0.36% | — | OpenvpnAIARM MbedtlsAI | 14/8/2026 | 1/9/2026 | OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field | |
| Aplazada | Media (6.8) | 0.43% | 💥 PoC | Embed Google Photos AlbumAI | 14/8/2026 | 26/8/2026 | The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Op-tee OSAIMbedtlsAINXP Se050AI | 10/8/2026 | 24/9/2026 | OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an input length… | |
| Aplazada | Media (6.5) | 0.29% | — | Davidartiss Code EmbedAI | 7/8/2026 | 9/9/2026 | The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper EmbedpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Embedded-solutions FreemodbusAI | 5/8/2026 | 26/8/2026 | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. | |
| Aplazada | Media (5.8) | 0.33% | — | Wpdeveloper EmbedpressAI | 4/8/2026 | 26/8/2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP requests to internal hosts and services that WordPress core URL validation does not cover (a blind… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Elearningfreak Insert OR Embed Articulate ContentAI | 3/8/2026 | 26/8/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers… | |
| Aplazada | Crítica (9.8) | 3.0% | 💥 Exploit | Advanced Responsive Video EmbedderAI | 29/7/2026 | 30/7/2026 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs… | |
| Aplazada | Alta (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Fediverse EmbedsAI | 9/7/2026 | 9/7/2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and… | |
| Aplazada | Media (5.3) | 0.31% | — | Fediverse EmbedsAI | 9/7/2026 | 9/7/2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body.… | |
| Aplazada | Alta (7.1) | 0.41% | — | Epiph Embed PrivacyAI | 29/6/2026 | 29/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpdeveloper EmbedpressAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. | |
| Pendiente de análisis | Alta (7) | 0.08% | — | Moxa Embedded Linux FirmwareAI | 12/6/2026 | 17/6/2026 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714.… | |
| Aplazada | Media (5.3) | 0.40% | — | Fediverse EmbedsAI | 11/6/2026 | 17/6/2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the attacker-supplied… | |
| Aplazada | Alta (7.5) | 0.41% | — | Fediverse EmbedsAI | 11/6/2026 | 17/6/2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($url) without enforcing… | |
| Pendiente de análisis | Alta (8.4) | 0.08% | — | Lenovo Thinkpad Embedded Controller FirmwareAI | 10/6/2026 | 7/10/2026 | During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. | |
| Analizada | Crítica (9.3) | 6.4% | ⚠ Explotación activa💥 Exploit | Checkpoint Gaia OSCheckpoint Gaia Embedded | 8/6/2026 | 4/8/2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | |
| Aplazada | Media (6.4) | 0.42% | — | Wpdeveloper EmbedpressAI | 6/6/2026 | 23/7/2026 | The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (4.3) | 0.41% | — | Wp-pdf PDF EmbedderAI | 28/5/2026 | 22/8/2026 | The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when… | |
| Aplazada | Media (6.4) | 0.32% | — | Responsive Video EmbedderAI | 27/5/2026 | 17/6/2026 | The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'list') in the video_shortcode()… | |
| Aplazada | Media (4.3) | 0.19% | — | Zawgyi EmbedAI | 12/5/2026 | 17/6/2026 | The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the zawgyi_adminpage function. This makes it possible for unauthenticated attackers to update the plugin's zawgyi_forceCSS setting by… | |
| Aplazada | Media (6.4) | 0.35% | — | Social Post EmbedAI | 28/4/2026 | 17/6/2026 | The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on the user-supplied URL. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.23% | — | Bplugins 3D Viewer Embed 3D ModelsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5. |