Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

51 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Themeisle Otter Blocks9/4/202417/6/2026
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaMedia (5.4)0.34%—Themeisle Otter Blocks29/3/202417/6/2026
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'. This…
ModificadaMedia (6.1)0.47%—Themeisle Otter Blocks13/3/202417/6/2026
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upload form, which allows SVG uploads, in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it…
ModificadaMedia (5.4)0.40%—Themeisle Otter Blocks13/3/202417/6/2026
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form file field CSS metabox in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaMedia (4.8)0.39%—Stpetedesign GPS Plotter17/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.1.4 versions.
ModificadaAlta (8.8)18%—Themeisle Otter30/5/202317/6/2026
The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.
ModificadaCrítica (9.8)1.1%—Antabot White-jotter Project Antabot White-jotter1/5/202317/6/2026
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload.
ModificadaMedia (6.5)2.3%—Kubernetes Container Storage Interface Snapshotter21/1/202117/6/2026
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically…
ModificadaMedia (5.3)0.92%—Huawei Alp-al00b FirmwareHuawei Alp-tl00b FirmwareHuawei Bla-al00b FirmwareHuawei Bla-tl00b Firmware+4614/12/201917/6/2026
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
ModificadaMedia (6.5)2.0%—Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform5/12/201917/6/2026
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,…
ModificadaAlta (8.1)2.7%💥 PoCGoogle AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…
ModificadaMedia (5.4)0.64%—Online Lottery PHP Readymade Script Project Online Lottery PHP Readymade Script29/3/201917/6/2026
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload.
ModificadaAlta (8.8)0.64%—Online Lottery PHP Readymade Script Project Online Lottery PHP Readymade Script29/3/201917/6/2026
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
ModificadaAlta (7.5)1.2%—Theethereumlottery THE Ethereum Lottery7/9/201817/6/2026
The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (which is private, yet predictable and readable by the eth.getStorageAt function). Therefore, it allows attackers to…
ModificadaAlta (7.5)1.1%—Lottery Project Lottery9/7/201817/6/2026
The mintToken function of a smart contract implementation for Lottery, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)1.4%—Inedo Otter1/12/201717/6/2026
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact, as demonstrated by the Plan Editor.
ModificadaCrítica (9.8)1.7%—Inedo Otter1/12/201717/6/2026
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.
ModificadaMedia (5.4)0.27%—Slingo Lottery Challenge9/9/201417/6/2026
The Slingo Lottery Challenge (aka com.slingo.slingolotterychallenge) application 1.0.34 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—CA Lottery Results Project CA Lottery Results9/9/201417/6/2026
The CA Lottery Results (aka com.matcho0.calotto) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Androkera LAS Vegas Lottery Scratch OFF9/9/201417/6/2026
The Las Vegas Lottery Scratch Off (aka com.androkera.lottery) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%💥 ExploitOtterware Statit9/10/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in statistik.php in Otterware StatIt 4 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter, (2) show parameter in a stat_tld action, or (3) order parameter in a stat_abfragen action.
ModificadaBaja (2.1)0.31%—Globetrotter Mobility Manager29/1/200716/6/2026
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots.
ModificadaAlta (7.5)3.5%💥 ExploitOtterware Letterit211/11/200616/6/2026
PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
ModificadaAlta (7.5)3.5%💥 ExploitOtterware Statit9/5/200616/6/2026
PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL in the statitpath parameter.
ModificadaMedia (5)1.3%—Globetrotter Flexlm25/9/199816/6/2026
The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.
Orbitaley — Vulnerabilidades