Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

2798 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.85%—Fearlessgeekmedia Fearlesscms10/12/202517/6/2026
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function.
ModificadaAlta (7.5)0.85%—Fearlessgeekmedia Fearlesscms10/12/202517/6/2026
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.
ModificadaMedia (6.1)0.26%—Fearlessgeekmedia Fearlesscms10/12/202517/6/2026
Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.
AplazadaAlta (7.6)0.34%—Wptinysolutions Media Library ToolsAI9/12/20257/10/2026
Neutralización Inadecuada de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') vulnerabilidad en Tiny Solutions Media Library Tools media-library-tools permite la inyección SQL. Este problema afecta a Media Library Tools: desde n/a hasta menor o igual que 1.6.15.
AplazadaMedia (5.3)0.35%—Davidlingren Media Library AssistantAI9/12/20257/10/2026
Vulnerabilidad de elusión de autorización a través de clave controlada por el usuario en el Asistente de Biblioteca de Medios de David Lingren permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Asistente de Biblioteca de Medios: desde n/a hasta 3.29.
AplazadaMedia (4.3)0.13%—M.code Media Library DownloaderAI9/12/20257/10/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Michael Revellin-Clerc Media Library Downloader media-library-downloader permite la falsificación de petición en sitios cruzados. Este problema afecta a Media Library Downloader: desde n/a hasta menor o igual que 1.4.0.
AplazadaMedia (4.3)0.13%—Wpmediadownload Media Library File DownloadAI9/12/20257/10/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en wpmediadownload Descarga de Archivos de la Biblioteca de Medios media-download permite la falsificación de petición en sitios cruzados. Este problema afecta a Descarga de Archivos de la Biblioteca de Medios: desde n/a hasta menor o igual que 1.4.
AnalizadaMedia (4.3)0.41%—Fastlinemedia Beaver Builder9/12/20257/10/2026
El plugin Beaver Builder - WordPress Page Builder para WordPress es vulnerable a la exposición de información sensible en todas las versiones hasta la 2.9.4, inclusive, a través de la función 'get_attachment_sizes'. Esto permite a atacantes autenticados, con acceso de nivel Colaborador o superior, extraer datos…
AnalizadaBaja (2.1)0.44%—Sobey Media Convergence System7/12/20257/10/2026
Se ha encontrado una vulnerabilidad en Sobey Media Convergence System 2.0/2.1. Esta vulnerabilidad afecta a código desconocido del archivo /sobey-mchEditor/watermark/upload. La manipulación del argumento File conduce a salto de ruta. El ataque puede iniciarse de forma remota. El exploit ha sido revelado al público y…
AplazadaAlta (8.7)0.35%—Request Serious Play Media PlayerAI5/12/202517/6/2026
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.
AplazadaCrítica (9.3)0.72%—Request Serious Play F3 Media ServerAI5/12/202517/6/2026
ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands as the web server user. Attackers can upload PHP executable files via the Quick File Uploader page, resulting in remote code execution on the server.
AplazadaAlta (8.7)0.37%—Request Serious Play F3 Media ServerAI5/12/202517/6/2026
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device.…
AnalizadaMedia (4.3)0.26%—Fastlinemedia Beaver Builder4/12/202517/6/2026
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is due to the plugin not properly verifying a user's authorization in the disable() function. This makes it possible for authenticated attackers, with contributor…
AnalizadaMedia (4.3)0.31%—Fastlinemedia Beaver Builder2/12/202517/6/2026
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient capability checks in the REST API endpoints under the 'fl-controls/v1' namespace that control site-wide Global Presets. This makes it possible…
AnalizadaMedia (5.3)0.37%—Mediatek Nr152/12/202517/6/2026
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01717526;…
ModificadaMedia (6.5)0.24%—Mediatek Nr152/12/202517/6/2026
En el Módem, existe una posible caída del sistema debido a un manejo de errores incorrecto. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del…
AnalizadaMedia (5.3)0.40%—Mediatek Nr152/12/202517/6/2026
En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría conducir a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción…
AnalizadaMedia (6.5)0.48%—Mediatek Nr15Mediatek Nr162/12/202517/6/2026
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673760;…
AnalizadaMedia (4.9)0.51%—Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r2/12/202517/6/2026
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673755; Issue…
ModificadaMedia (6.5)0.25%—Mediatek Nr152/12/202517/6/2026
En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. La interacción del usuario…
ModificadaMedia (6.5)0.25%—Mediatek Nr152/12/202517/6/2026
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673749; Issue ID:…
AnalizadaMedia (5.3)0.49%—Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r2/12/202517/6/2026
In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689251;…
AnalizadaMedia (5.3)0.49%—Mediatek Nr15Mediatek Nr162/12/202517/6/2026
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689252; Issue…
ModificadaMedia (6.5)0.24%—Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r2/12/202517/6/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01270690; Issue…
ModificadaMedia (6.5)0.24%—Mediatek Nr152/12/202517/6/2026
En el Módem, existe una posible caída del sistema debido a una falta de verificación de límites. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción…