Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.36% | — | Wpcompress WP Compress | 4/1/2025 | 17/6/2026 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Media (6.1) | 0.44% | — | Imagerecycle PDF & Image Compression | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression imagerecycle-pdf-image-compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through <= 3.1.16. | |
| Aplazada | Alta (7.3) | 0.23% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.6) | 0.34% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Media (5.1) | 0.26% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Alta (7.7) | 0.31% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (6.1) | 0.29% | — | Wpcompress WP Compress | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Reflected XSS.This issue affects WP Compress: from n/a through <= 6.20.13. | |
| Aplazada | Media (5.4) | 0.18% | — | Tinypng Tiny Compress ImagesAI | 5/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG TinyPNG tiny-compress-images allows Cross Site Request Forgery.This issue affects TinyPNG: from n/a through <= 3.4.3. | |
| Analizada | Media (4.3) | 0.19% | — | Imagerecycle PDF & Image Compression | 24/8/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated… | |
| Analizada | Media (4.3) | 0.26% | — | Imagerecycle PDF & Image Compression | 24/8/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform… | |
| Modificada | Media (4.3) | 0.32% | — | Himalayasaxena Highcompress Image Compressor | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0. | |
| Aplazada | Alta (8.6) | 0.50% | 💥 PoC | Airlift AircompressorAI | 29/5/2024 | 17/6/2026 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompressor implementations of Aircompressor (LZ4, LZO, Snappy, Zstandard) can crash the JVM for certain input, and in some cases also leak the content of other memory of the Java process (which could… | |
| Aplazada | Crítica (10) | 36% | 💥 Exploit | Intel Neural CompressorAI | 16/5/2024 | 17/6/2026 | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access. | |
| Aplazada | Media (4.7) | 0.14% | — | Intel Neural CompressorAI | 16/5/2024 | 17/6/2026 | Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.3) | 0.34% | — | Wpcompress WP Compress | 14/5/2024 | 17/6/2026 | The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above,… | |
| Modificada | Media (6.1) | 0.44% | — | Wpcompress WP Compress | 14/5/2024 | 17/6/2026 | The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to… | |
| Modificada | Alta (8.8) | 0.23% | — | Wpcompress WP Compress | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.10.35. | |
| Modificada | Alta (7.5) | 0.72% | — | Wpcompress WP Compress | 9/4/2024 | 17/6/2026 | The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for unauthenticated attackers to reset the CDN region and… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possible for unauthenticated attackers to remove all plugin data via a… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the stopOptimizeAll function. This makes it possible for unauthenticated attackers to modify image optimization… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the optimizeAllOn function. This makes it possible for unauthenticated attackers to modify image optimization… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the disableOptimization function. This makes it possible for unauthenticated attackers to disable the image… | |
| Modificada | Media (4.3) | 0.25% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the enableOptimization function. This makes it possible for unauthenticated attackers to enable image… | |
| Modificada | Media (4.3) | 0.35% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.35% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to… |