Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.62%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional14/11/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3.
AplazadaMedia (5.4)0.15%—Intel Advanced Link Analyzer Standard EditionAI13/11/202417/6/2026
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.18%—Intel High Level Synthesis CompilerAIIntel Quartus Prime PRO EditionAI13/11/202417/6/2026
Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software for Intel(R) Quartus(R) Prime Pro Edition Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.1)0.35%—Froala Wysiwyg EditorAI7/11/202417/6/2026
Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.
ModificadaAlta (8.8)0.37%—Wpchill Htaccess File Editor1/11/202417/6/2026
Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Htaccess File Editor: from n/a through <= 1.0.18.
AplazadaMedia (6.5)0.27%—Faceleg Raptor EditorAI28/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faceleg Raptor Editor wp-raptor allows DOM-Based XSS.This issue affects Raptor Editor: from n/a through <= 1.0.20.
AplazadaMedia (6.4)0.34%—Editor Custom Color PaletteAI26/10/202417/6/2026
The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to…
AplazadaCrítica (9.8)36%💥 PoCWUX Blog EditorAI26/10/202417/6/2026
The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which…
AplazadaCrítica (9.8)0.56%—WUX Blog EditorAI26/10/202417/6/2026
The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user.
AplazadaMedia (4.3)0.28%—Sovrn Editorial AssistantAI26/10/202417/6/2026
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (8.6)0.50%—Ininet Solutions Spidercontrol Scada PC HMI EditorAI24/10/202417/6/2026
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup…
AnalizadaMedia (6.1)0.34%—Edit Woocommerce Templates Project Edit Woocommerce Templates18/10/202417/6/2026
The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (8.5)0.42%—Wpgrim Classic Editor AND Classic WidgetsAI17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Grim Classic Editor and Classic Widgets classic-editor-and-classic-widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through <= 1.4.1.
AplazadaMedia (6.5)0.43%—ACF Quick Edit FieldsAI16/10/202417/6/2026
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.
AplazadaCrítica (9.8)0.76%—Wanxing Technology Yitu Project Management Kirin EditionAI15/10/202417/6/2026
An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.
AplazadaMedia (5.3)0.49%—D-zero CO LTD BurgereditorAID-zero CO LTD Burgereditor Limited EditionAIBasercmsAI11/10/20245/7/2026
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.
AnalizadaAlta (7)0.67%—Paloaltonetworks Expedition9/10/202417/6/2026
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.
ModificadaAlta (8.2)14%💥 PoCPaloaltonetworks Expedition9/10/202417/6/2026
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.
AnalizadaCrítica (9.2)100%⚠ Explotación activa💥 ExploitPaloaltonetworks Expedition9/10/202417/6/2026
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
ModificadaCrítica (9.3)83%💥 PoCPaloaltonetworks Expedition9/10/202417/6/2026
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
AnalizadaCrítica (9.9)99%⚠ Explotación activa💥 ExploitPaloaltonetworks Expedition9/10/202417/6/2026
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
AplazadaAlta (7.1)0.32%—Yellopencil Visual CSS Style EditorAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YellowPencil YellowPencil Visual CSS Style Editor yellow-pencil-visual-theme-customizer allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through <= 7.6.4.
AnalizadaMedia (6.1)0.45%—Themehigh Checkout Field Editor FOR Woocommerce4/10/202417/6/2026
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.4)0.16%—Foxit PDF ReaderAIFoxit PDF EditorAI26/9/202417/6/2026
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.
ModificadaMedia (5.1)0.52%—Ckeditor525/9/202417/6/2026
CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the…