Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Iframe Shortcode Project Iframe Shortcode | 26/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions. | |
| Modificada | Crítica (9.8) | 1.8% | — | Yiiframework YII | 4/4/2023 | 17/6/2026 | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework. | |
| Modificada | Alta (8.8) | 1.5% | — | Yiiframework GII | 21/1/2023 | 17/6/2026 | Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file. | |
| Modificada | Media (5.4) | 0.61% | — | Yiiframework GII | 9/12/2022 | 17/6/2026 | Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field. | |
| Modificada | Crítica (9.8) | 1.2% | — | Yiiframework YII | 23/11/2022 | 17/6/2026 | `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27. | |
| Modificada | Media (6.1) | 0.80% | — | Tinywebgallery Advanced Iframe | 7/3/2022 | 17/6/2026 | The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.3) | 1.7% | — | Yiiframework YII | 10/8/2021 | 17/6/2026 | yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator | |
| Modificada | Alta (7.5) | 1.9% | — | Yiiframework YII | 10/8/2021 | 17/6/2026 | yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator | |
| Modificada | Crítica (10) | 78% | — | Yiiframework YII | 15/9/2020 | 17/6/2026 | Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory. | |
| Modificada | Media (6.1) | 2.0% | — | Iframe Project Iframe | 7/5/2020 | 17/6/2026 | The iframe plugin before 4.5 for WordPress does not sanitize a URL. | |
| Modificada | Media (5.9) | 0.54% | — | Yiiframework YII | 28/1/2019 | 17/6/2026 | Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. | |
| Modificada | Alta (8.1) | 1.5% | — | Yiiframework YII | 21/3/2018 | 17/6/2026 | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension. | |
| Modificada | Crítica (9.8) | 1.6% | — | Yiiframework YII | 21/3/2018 | 17/6/2026 | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension. | |
| Modificada | Crítica (9.8) | 1.9% | — | Yiiframework YII | 21/3/2018 | 17/6/2026 | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input. | |
| Modificada | Alta (7.5) | 2.9% | — | Yiiframework | 22/1/2018 | 17/6/2026 | In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php. | |
| Modificada | Alta (8.8) | 0.60% | — | Yiiframework | 22/1/2018 | 17/6/2026 | In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity. | |
| Modificada | Media (6.1) | 0.83% | — | Yiiframework YII | 21/7/2017 | 17/6/2026 | An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled. | |
| Modificada | Media (4.3) | 2.4% | — | Yiiframework | 14/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7. | |
| Modificada | Alta (7.5) | 2.1% | — | Yiiframework | 3/7/2014 | 17/6/2026 | The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property. | |
| Modificada | Alta (9.3) | 3.1% | — | Php-nuke Iframe Module | 23/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Dotnetnuke Iframe | 1/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values." |