Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Themeisle Otter Blocks | 9/4/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (5.4) | 0.34% | — | Themeisle Otter Blocks | 29/3/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'. This… | |
| Modificada | Media (6.1) | 0.47% | — | Themeisle Otter Blocks | 13/3/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it… | |
| Modificada | Media (5.4) | 0.40% | — | Themeisle Otter Blocks | 13/3/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (4.8) | 0.39% | — | Stpetedesign GPS Plotter | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.1.4 versions. | |
| Modificada | Alta (8.8) | 18% | — | Themeisle Otter | 30/5/2023 | 17/6/2026 | The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper. | |
| Modificada | Crítica (9.8) | 1.1% | — | Antabot White-jotter Project Antabot White-jotter | 1/5/2023 | 17/6/2026 | File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload. | |
| Modificada | Media (6.5) | 2.3% | — | Kubernetes Container Storage Interface Snapshotter | 21/1/2021 | 17/6/2026 | Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically… | |
| Modificada | Media (5.3) | 0.92% | — | Huawei Alp-al00b FirmwareHuawei Alp-tl00b FirmwareHuawei Bla-al00b FirmwareHuawei Bla-tl00b Firmware+46 | 14/12/2019 | 17/6/2026 | Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal. | |
| Modificada | Media (6.5) | 2.0% | — | Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform | 5/12/2019 | 17/6/2026 | Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,… | |
| Modificada | Alta (8.1) | 2.7% | 💥 PoC | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Media (5.4) | 0.64% | — | Online Lottery PHP Readymade Script Project Online Lottery PHP Readymade Script | 29/3/2019 | 17/6/2026 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload. | |
| Modificada | Alta (8.8) | 0.64% | — | Online Lottery PHP Readymade Script Project Online Lottery PHP Readymade Script | 29/3/2019 | 17/6/2026 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions. | |
| Modificada | Alta (7.5) | 1.2% | — | Theethereumlottery THE Ethereum Lottery | 7/9/2018 | 17/6/2026 | The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (which is private, yet predictable and readable by the eth.getStorageAt function). Therefore, it allows attackers to… | |
| Modificada | Alta (7.5) | 1.1% | — | Lottery Project Lottery | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Lottery, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 1.4% | — | Inedo Otter | 1/12/2017 | 17/6/2026 | Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact, as demonstrated by the Plan Editor. | |
| Modificada | Crítica (9.8) | 1.7% | — | Inedo Otter | 1/12/2017 | 17/6/2026 | Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181. | |
| Modificada | Media (5.4) | 0.27% | — | Slingo Lottery Challenge | 9/9/2014 | 17/6/2026 | The Slingo Lottery Challenge (aka com.slingo.slingolotterychallenge) application 1.0.34 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | CA Lottery Results Project CA Lottery Results | 9/9/2014 | 17/6/2026 | The CA Lottery Results (aka com.matcho0.calotto) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Androkera LAS Vegas Lottery Scratch OFF | 9/9/2014 | 17/6/2026 | The Las Vegas Lottery Scratch Off (aka com.androkera.lottery) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Otterware Statit | 9/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in statistik.php in Otterware StatIt 4 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter, (2) show parameter in a stat_tld action, or (3) order parameter in a stat_abfragen action. | |
| Modificada | Baja (2.1) | 0.31% | — | Globetrotter Mobility Manager | 29/1/2007 | 16/6/2026 | The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Otterware Letterit2 | 11/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Otterware Statit | 9/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL in the statitpath parameter. | |
| Modificada | Media (5) | 1.3% | — | Globetrotter Flexlm | 25/9/1998 | 16/6/2026 | The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command. |