Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.62% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 14/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3. | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Advanced Link Analyzer Standard EditionAI | 13/11/2024 | 17/6/2026 | Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel High Level Synthesis CompilerAIIntel Quartus Prime PRO EditionAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software for Intel(R) Quartus(R) Prime Pro Edition Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.1) | 0.35% | — | Froala Wysiwyg EditorAI | 7/11/2024 | 17/6/2026 | Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier. | |
| Modificada | Alta (8.8) | 0.37% | — | Wpchill Htaccess File Editor | 1/11/2024 | 17/6/2026 | Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Htaccess File Editor: from n/a through <= 1.0.18. | |
| Aplazada | Media (6.5) | 0.27% | — | Faceleg Raptor EditorAI | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faceleg Raptor Editor wp-raptor allows DOM-Based XSS.This issue affects Raptor Editor: from n/a through <= 1.0.20. | |
| Aplazada | Media (6.4) | 0.34% | — | Editor Custom Color PaletteAI | 26/10/2024 | 17/6/2026 | The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Crítica (9.8) | 36% | 💥 PoC | WUX Blog EditorAI | 26/10/2024 | 17/6/2026 | The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Crítica (9.8) | 0.56% | — | WUX Blog EditorAI | 26/10/2024 | 17/6/2026 | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user. | |
| Aplazada | Media (4.3) | 0.28% | — | Sovrn Editorial AssistantAI | 26/10/2024 | 17/6/2026 | The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (8.6) | 0.50% | — | Ininet Solutions Spidercontrol Scada PC HMI EditorAI | 24/10/2024 | 17/6/2026 | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup… | |
| Analizada | Media (6.1) | 0.34% | — | Edit Woocommerce Templates Project Edit Woocommerce Templates | 18/10/2024 | 17/6/2026 | The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.5) | 0.42% | — | Wpgrim Classic Editor AND Classic WidgetsAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Grim Classic Editor and Classic Widgets classic-editor-and-classic-widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.43% | — | ACF Quick Edit FieldsAI | 16/10/2024 | 17/6/2026 | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above. | |
| Aplazada | Crítica (9.8) | 0.76% | — | Wanxing Technology Yitu Project Management Kirin EditionAI | 15/10/2024 | 17/6/2026 | An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat. | |
| Aplazada | Media (5.3) | 0.49% | — | D-zero CO LTD BurgereditorAID-zero CO LTD Burgereditor Limited EditionAIBasercmsAI | 11/10/2024 | 5/7/2026 | A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files. | |
| Analizada | Alta (7) | 0.67% | — | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft. | |
| Modificada | Alta (8.2) | 14% | 💥 PoC | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials. | |
| Analizada | Crítica (9.2) | 100% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. | |
| Modificada | Crítica (9.3) | 83% | 💥 PoC | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | |
| Analizada | Crítica (9.9) | 99% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | |
| Aplazada | Alta (7.1) | 0.32% | — | Yellopencil Visual CSS Style EditorAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YellowPencil YellowPencil Visual CSS Style Editor yellow-pencil-visual-theme-customizer allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through <= 7.6.4. | |
| Analizada | Media (6.1) | 0.45% | — | Themehigh Checkout Field Editor FOR Woocommerce | 4/10/2024 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.4) | 0.16% | — | Foxit PDF ReaderAIFoxit PDF EditorAI | 26/9/2024 | 17/6/2026 | In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed. | |
| Modificada | Media (5.1) | 0.52% | — | Ckeditor5 | 25/9/2024 | 17/6/2026 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the… |