Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.35% | — | Avideo SocialmediapublisherAIWwbn AvideoAI | 8/9/2026 | 8/9/2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored… | |
| Aplazada | Alta (7.1) | 0.25% | — | Podlove Podcast PublisherAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle BI Publisher | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. While the vulnerability… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle BI Publisher | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful… | |
| Analizada | Alta (8.5) | 0.38% | — | Oracle BI Publisher | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While… | |
| Analizada | Alta (8.3) | 0.39% | — | Oracle BI Publisher | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.… | |
| Aplazada | Alta (8.8) | 1.1% | — | Podlove Podcast PublisherAI | 16/8/2026 | 20/8/2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete… | |
| Aplazada | Media (4.3) | 0.28% | — | Swagger UIAIWso2 API PublisherAI | 6/8/2026 | 29/9/2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API… | |
| Aplazada | Media (4.6) | 0.23% | — | Narrative PublisherAI | 2/8/2026 | 26/8/2026 | The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post. | |
| Aplazada | Media (4.3) | 0.14% | — | Podlove Podcast PublisherAI | 1/8/2026 | 26/8/2026 | The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page. | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle BI Publisher | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the… | |
| Analizada | Media (6.5) | 0.39% | — | Oracle BI Publisher | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle BI Publisher | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks… | |
| Aplazada | Crítica (9.8) | 3.8% | 💥 Exploit | Podlove Podcast PublisherAI | 14/7/2026 | 14/7/2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Media (6.4) | 0.32% | — | Epaperflip PublisherAI | 9/6/2026 | 23/7/2026 | The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed` shortcode in all versions up to, and including, 1. This is due to insufficient input sanitization and output escaping on the shortcode attribute which is injected… | |
| Analizada | Alta (8) | 0.50% | — | Jenkins Html Publisher | 29/4/2026 | 17/6/2026 | Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Aplazada | Media (5.3) | 0.26% | — | THE Publisher Desk ADS TXTAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in PublisherDesk The Publisher Desk ads.txt the-publisher-desk-ads-txt allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Publisher Desk ads.txt: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Podlove Podcast PublisherAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a through <= 4.3.3. | |
| Aplazada | Media (5.1) | 0.14% | — | Flexnet PublisherAI | 11/2/2026 | 17/6/2026 | FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined… | |
| Modificada | Alta (8.5) | 0.22% | — | Primera Ptpublisher | 13/1/2026 | 17/6/2026 | PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Primera Technology\PTPublisher\UsbFlashDongleService.exe' to inject… | |
| Modificada | Media (4.3) | 0.26% | — | Jenkins Curseforge Publisher | 29/10/2025 | 17/6/2026 | Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.17% | — | Jenkins Curseforge Publisher | 29/10/2025 | 17/6/2026 | Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system. | |
| Aplazada | Media (6.4) | 0.19% | — | BG Book PublisherAI | 22/10/2025 | 17/6/2026 | The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta, rendered through the `[book_author]` shortcode, in all versions up to, and including, 1.25. This is due to the plugin not properly escaping the meta value before output. This makes it possible for… | |
| Analizada | Media (6.5) | 0.33% | — | Oracle BI Publisher | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this… | |
| Aplazada | Media (4.3) | 0.17% | — | Contentmx Content PublisherAI | 3/10/2025 | 17/6/2026 | The ContentMX Content Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the cmx_activate_connection function. This makes it possible for unauthenticated attackers to bind their own ContentMX… |