Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Iframe Shortcode Project Iframe Shortcode26/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions.
ModificadaCrítica (9.8)1.8%—Yiiframework YII4/4/202317/6/2026
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
ModificadaAlta (8.8)1.5%—Yiiframework GII21/1/202317/6/2026
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
ModificadaMedia (5.4)0.61%—Yiiframework GII9/12/202217/6/2026
Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
ModificadaCrítica (9.8)1.2%—Yiiframework YII23/11/202217/6/2026
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.
ModificadaMedia (6.1)0.80%—Tinywebgallery Advanced Iframe7/3/202217/6/2026
The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.3)1.7%—Yiiframework YII10/8/202117/6/2026
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
ModificadaAlta (7.5)1.9%—Yiiframework YII10/8/202117/6/2026
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
ModificadaCrítica (10)78%—Yiiframework YII15/9/202017/6/2026
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.
ModificadaMedia (6.1)2.0%—Iframe Project Iframe7/5/202017/6/2026
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
ModificadaMedia (5.9)0.54%—Yiiframework YII28/1/201917/6/2026
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
ModificadaAlta (8.1)1.5%—Yiiframework YII21/3/201817/6/2026
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
ModificadaCrítica (9.8)1.6%—Yiiframework YII21/3/201817/6/2026
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension.
ModificadaCrítica (9.8)1.9%—Yiiframework YII21/3/201817/6/2026
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
ModificadaAlta (7.5)2.9%—Yiiframework22/1/201817/6/2026
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.
ModificadaAlta (8.8)0.60%—Yiiframework22/1/201817/6/2026
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
ModificadaMedia (6.1)0.83%—Yiiframework YII21/7/201717/6/2026
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
ModificadaMedia (4.3)2.4%—Yiiframework14/5/201517/6/2026
Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7.
ModificadaAlta (7.5)2.1%—Yiiframework3/7/201417/6/2026
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.
ModificadaAlta (9.3)3.1%—Php-nuke Iframe Module23/3/200716/6/2026
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.
ModificadaMedia (6.8)1.2%—Dotnetnuke Iframe1/2/200716/6/2026
Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."