Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.37%—Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+1110/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes…
ModificadaMedia (6.1)1.3%💥 ExploitDeconf Analytics Insights12/2/202417/6/2026
The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick…
ModificadaAlta (7.8)0.19%—Progress Telerik Justdecompile31/1/202417/6/2026
In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate…
ModificadaAlta (8.8)1.1%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware+111/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
ModificadaAlta (8.8)0.53%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware11/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.
ModificadaAlta (7.5)0.73%—Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+118/12/202317/6/2026
An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.
ModificadaMedia (6.1)0.40%—Deconf Clicky Analytics Dashboard14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
ModificadaAlta (8.8)0.30%—Webtoffee Decorator30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce Email Customizer: from n/a through 1.2.7.
ModificadaCrítica (9.8)4.2%—Moses-smt Mosesdecoder27/11/202317/6/2026
A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iSenWeb/trans_result.php. The manipulation of the argument input1 leads to os command injection. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (6.1)0.50%—Jenkins AWS Codecommit Trigger6/9/202317/6/2026
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability.
ModificadaMedia (6.5)0.64%—Jenkins AWS Codecommit Trigger6/9/202317/6/2026
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue.
ModificadaMedia (4.3)0.33%—Jenkins AWS Codecommit Trigger6/9/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers to clear the SQS queue.
ModificadaMedia (4.3)0.45%—Jenkins AWS Codecommit Trigger6/9/202317/6/2026
A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.
ModificadaAlta (8)0.40%—Tp-link Deco M4 Firmware6/9/202317/6/2026
Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
ModificadaMedia (5.4)0.36%—Wpruse ART Decoration Shortcode1/9/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Artem Abramovich Art Decoration Shortcode plugin <= 1.5.6 versions.
ModificadaMedia (4.8)0.37%—Decondigital Decon WP SMS8/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Decon Digital Decon WP SMS plugin <= 1.1 versions.
ModificadaMedia (4.8)0.44%—Codecolorer Project Codecolorer27/6/202317/6/2026
The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.5)0.63%—Jenkins AWS Codecommit Trigger14/6/202317/6/2026
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.
ModificadaMedia (6.1)0.45%—Udecode Plate9/6/202317/6/2026
@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor…
ModificadaAlta (8.8)1.9%—Bytedeco Javacpp Presets9/6/202317/6/2026
JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.event.head_commit.message​` parameter in an insecure way. For example, the commit message is used in a run statement - resulting in a command injection vulnerability due…
ModificadaMedia (5.3)0.57%—Juniper Appid Service SigpackJuniper Jdpi-decoder EngineJuniper Junos17/4/202317/6/2026
—
ModificadaAlta (7.1)0.51%—Nongnu Dmidecode13/4/202317/6/2026
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents…
ModificadaMedia (6.5)0.89%—Decode-uri-component Project Decode-uri-componentElastic Kibana8/2/202317/6/2026
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
ModificadaAlta (7.5)24%—Decode-uri-component Project Decode-uri-component28/11/202217/6/2026
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
ModificadaMedia (5.9)0.36%—Bosch Video Management SystemBosch Videojet Decoder 7513 Firmware30/9/202217/6/2026
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or…
Orbitaley — Vulnerabilidades