Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.94% | — | Oxygenz Clipbucket | 17/10/2025 | 17/6/2026 | ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of the file-loading path is inadequate, allowing authenticated administrators to read and write arbitrary files outside the… | |
| Analizada | Alta (7.2) | 0.52% | — | Oxygenz Clipbucket | 16/10/2025 | 17/6/2026 | ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability requires access privileges to the Admin Area. | |
| Aplazada | Media (6.5) | 0.38% | — | Mediawiki BucketAI | 6/10/2025 | 17/6/2026 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recursion can occur if a user queries a bucket using the `!=` comparator. This will result in PHP's call stack limit exceeding, and/or increased memory consumption, potentially leading to a denial of… | |
| Aplazada | Media (6.5) | 0.20% | — | Matthewordie BucketsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthewordie Buckets buckets allows Stored XSS.This issue affects Buckets: from n/a through <= 0.3.9. | |
| Analizada | Alta (7.3) | 1.5% | 💥 Exploit | Oxygenz Clipbucket | 18/9/2025 | 17/6/2026 | An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler | |
| Analizada | Media (6.5) | 1.1% | 💥 Exploit | Oxygenz Clipbucket | 18/9/2025 | 17/6/2026 | An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter | |
| Analizada | Crítica (10) | 3.7% | 💥 Exploit | Clip-bucket Clipbucket | 31/7/2025 | 16/6/2026 | ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable… | |
| Aplazada | Alta (7.7) | 0.76% | — | Files-bucket-serverAI | 23/7/2025 | 17/6/2026 | All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files outside of the intended directory. | |
| Analizada | Media (6.1) | 0.31% | — | Optimalaccess Kbucket | 15/5/2025 | 17/6/2026 | The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin. | |
| Analizada | Media (4.8) | 0.32% | — | Optimalaccess Kbucket | 15/5/2025 | 17/6/2026 | The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (5.4) | 0.16% | — | FeedbucketAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Feedbucket Feedbucket – Website Feedback Tool feedbucket allows Cross Site Request Forgery.This issue affects Feedbucket – Website Feedback Tool: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.1) | 0.19% | — | Optimalaccess KbucketAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects KBucket: from n/a through <= 4.1.6. | |
| Analizada | Alta (8.8) | 0.30% | — | Jenkins Bitbucket Server Integration | 22/1/2025 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. | |
| Analizada | Crítica (9.8) | 1.2% | — | Oxygenz Clipbucket | 7/1/2025 | 17/6/2026 | ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can upload a PHP script file instead of an… | |
| Analizada | Alta (7.5) | 1.1% | — | Oxygenz Clipbucket | 7/1/2025 | 17/6/2026 | ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the template directory via a directory traversal, which results in a denial of service. | |
| Analizada | Crítica (9.1) | 0.96% | — | Oxygenz Clipbucket | 7/1/2025 | 17/6/2026 | ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avatar at any time. During deletion, ClipBucket checks for the avatar_url as a filepath within the avatars subdirectory. If the URL path exists within the avatars directory,… | |
| Analizada | Crítica (9.8) | 0.75% | — | Oxygenz Clipbucket | 6/12/2024 | 17/6/2026 | ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/upload.php where the user supplied input via collection get parameter is directly provided to unserialize function. As a… | |
| Analizada | Alta (8.8) | 0.75% | — | Oxygenz Clipbucket | 6/12/2024 | 17/6/2026 | ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/photo_upload.php within the decode_key function. User inputs were supplied to this function without sanitization via… | |
| Aplazada | Media (6.5) | 0.25% | — | Codexshaper Advanced Element Bucket Addons FOR ElementorAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codexshaper Advanced Element Bucket Addons for Elementor cs-element-bucket allows Stored XSS.This issue affects Advanced Element Bucket Addons for Elementor: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.33% | — | Kevinabl Adventure Bucket ListAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevinabl Adventure Bucket List adventure-bucket-list allows DOM-Based XSS.This issue affects Adventure Bucket List: from n/a through <= 1.0.9. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Optimalaccess KbucketAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shell to a Web Server.This issue affects KBucket: from n/a through <= 4.2.2. | |
| Analizada | Media (4.3) | 0.25% | — | Atlassian Bitbucket Data Center | 24/7/2024 | 17/6/2026 | There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector… | |
| Analizada | Media (4.3) | 0.49% | — | Jenkins Bitbucket Branch Source | 26/6/2024 | 17/6/2026 | Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases. | |
| Analizada | Alta (8) | 1.3% | 💥 PoC | Jenkins Gitbucket | 6/3/2024 | 17/6/2026 | Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs. | |
| Analizada | Media (6.3) | 0.56% | — | Jenkins Bitbucket Branch Source | 6/3/2024 | 17/6/2026 | In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server. |