Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.79% | — | Ublockorigin Ublock OriginDebian Linux | 2/5/2025 | 17/6/2026 | A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack… | |
| Aplazada | Crítica (9.3) | 0.59% | — | Origincode Product CatalogAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog displayproduct allows SQL Injection.This issue affects Product Catalog: from n/a through <= 1.0.4. | |
| Modificada | Alta (8.8) | 0.19% | — | Carlosminatti Delete Original Image | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This issue affects Delete Original Image: from n/a through <= 0.4. | |
| Analizada | Media (5.4) | 0.24% | — | Siteorigin Page Builder | 1/3/2025 | 17/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (7.3) | 0.17% | — | Electronic Arts Dragon AGE OriginsAI | 27/1/2025 | 17/6/2026 | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to… | |
| Analizada | Media (5.4) | 0.33% | — | Siteorigin Page Builder | 14/1/2025 | 17/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Modificada | Alta (8.8) | 0.60% | — | Siteorigin Widgets Bundle | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Greg - SiteOrigin SiteOrigin Widgets Bundle so-widgets-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteOrigin Widgets Bundle: from n/a through <= 1.64.0. | |
| Analizada | Media (5.4) | 0.39% | — | Siteorigin Widgets Bundle | 30/7/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget in all versions up to, and including, 1.62.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.30% | — | Siteorigin Widgets Bundle | 11/6/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versions up to, and including, 1.61.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.36% | — | Siteorigin Widgets Bundle | 22/5/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 1.60.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.36% | — | Siteorigin Page Builder | 21/5/2024 | 17/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.43% | — | Siteorigin Page Builder | 23/3/2024 | 17/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (5.4) | 0.50% | — | Siteorigin Widgets Bundle | 13/3/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.58.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject… | |
| Modificada | Media (5.4) | 0.53% | — | Siteorigin Widgets Bundle | 29/2/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribute in all versions up to, and including, 1.58.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to… | |
| Modificada | Media (5.4) | 0.44% | — | Siteorigin Widgets Bundle | 29/2/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick parameter in all versions up to, and including, 1.58.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to… | |
| Modificada | Media (5.4) | 0.53% | — | Siteorigin Widgets Bundle | 5/2/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject… | |
| Modificada | Alta (7.2) | 1.0% | — | Siteorigin Widgets Bundle | 18/12/2023 | 17/6/2026 | The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites. | |
| Modificada | Alta (7.5) | 0.28% | — | Koajs Cross-origin Resource Sharing FOR KOA | 11/12/2023 | 17/6/2026 | @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-Origin` header with the value of the origin from the request. This behavior… | |
| Modificada | Alta (8.8) | 0.21% | — | Zixn Original Texts Yandex Webmaster | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions. | |
| Modificada | Media (4.3) | 0.40% | — | Origincode Photo-contest | 1/7/2023 | 17/6/2026 | The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the load_images_thumbnail() and edit_gallery() functions. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (4.8) | 0.39% | — | Rvola WP Original Media Path | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in RVOLA WP Original Media Path plugin <= 2.4.0 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Fico Origination Manager Decision | 9/5/2023 | 9/7/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (7.5) | 0.72% | — | Fico Origination Manager Decision | 9/5/2023 | 9/7/2026 | A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie. | |
| Modificada | Media (6.1) | 0.64% | — | Ublock Origin Project Ublock Origin | 13/7/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process. | |
| Modificada | Media (5.3) | 0.74% | — | Openshift Origin | 7/7/2022 | 17/6/2026 | In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes. |