Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

255 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.34%—Maxfoundry Maxbuttons20/12/202417/6/2026
The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (6.5)0.38%—Palantir FoundryAI2/12/202417/6/2026
Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational…
AplazadaMedia (5.3)0.40%—Cloudfoundry CapiAICloudfoundry Cf-deploymentAI11/11/202417/6/2026
Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service attack against Cloud Controller. The Cloud Foundry project recommends upgrading the following releases:
AnalizadaMedia (6.1)0.40%—Maxfoundry Social Share Buttons19/10/202417/6/2026
The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.19. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaMedia (6.3)0.33%—Maxfoundry Media Library Folders30/8/202417/6/2026
The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaMedia (6.5)0.45%—Maxfoundry Media Library Folders29/8/202417/6/2026
The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AnalizadaMedia (5.3)0.44%—Maxfoundry Maxbuttons24/8/202417/6/2026
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to…
AnalizadaMedia (5.4)0.49%—Maxfoundry Maxbuttons13/7/202417/6/2026
The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks
AplazadaCrítica (9.1)0.55%—Cloudfoundry Haproxy-boshreleaseAICloudfoundry Routing-releaseAICloudfoundry Cloud FoundryAI3/7/202417/6/2026
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the…
AplazadaMedia (6.4)0.27%—Maxfoundry MaxgalleriaAI18/6/202417/6/2026
The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shortcode in all versions up to, and including, 6.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaAlta (7.5)0.40%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release10/6/202417/6/2026
Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale.
AplazadaMedia (4.3)0.61%—Maxfoundry MaxgalleriaAI2/5/202417/6/2026
The MaxGalleria plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the add_media_library_images_to_gallery function in all versions up to, and including, 6.4.2. This makes it possible for authenticated attackers, with subscriber access or above, to upload arbitrary…
ModificadaMedia (6.1)0.39%—Maxfoundry Media Library Folders19/4/202417/6/2026
The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (6.5)0.66%—Maxfoundry Media Library Folders10/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8.
ModificadaAlta (8.8)0.58%—Maxfoundry Media Library Folders29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.7.
ModificadaMedia (5.4)0.40%—Maxfoundry Maxbuttons5/2/202417/6/2026
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including 9.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
ModificadaAlta (7.5)0.54%—Pivotal Cloud Foundry DeploymentPivotal Cloud Foundry Routing Release12/1/202417/6/2026
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.
ModificadaMedia (4.8)0.32%—Maxfoundry Maxbuttons9/1/202417/6/2026
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
ModificadaMedia (5.3)0.44%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release8/9/202317/6/2026
Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations.
ModificadaMedia (4.3)0.44%—Palantir Foundry3/8/202317/6/2026
A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .
ModificadaMedia (5.9)0.41%—Palantir Foundry Campaigns3/8/202317/6/2026
The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint
ModificadaMedia (5.4)0.38%—Maxfoundry Maxbuttons25/7/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Max Foundry WordPress Button Plugin MaxButtons plugin <= 9.5.3 versions.
ModificadaMedia (5.4)0.38%—Palantir Foundry Frontend10/7/202317/6/2026
A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.229.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
ModificadaMedia (4.3)0.40%—Palantir Foundry Job-tracker10/7/202317/6/2026
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
ModificadaMedia (5.3)0.46%—Palantir Foundry Comments10/7/202317/6/2026
A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.