Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.94% | 💥 PoC | Podlove Podcast PublisherAI | 23/9/2025 | 17/6/2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Media (4.7) | 0.21% | — | Podlove Podcast PublisherAI | 27/8/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Phishing.This issue affects Podlove Podcast Publisher: from n/a through <= 4.2.5. | |
| Analizada | Alta (8.1) | 0.30% | — | Oracle BI Publisher | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks… | |
| Modificada | Media (6.3) | 0.47% | — | Jenkins Html Publisher | 9/7/2025 | 17/6/2026 | Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the Jenkins controller file system in the build log. | |
| Analizada | Media (4.8) | 0.31% | — | Podlove Podcast Publisher | 15/5/2025 | 17/6/2026 | The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Podlove Podcast Publisher | 15/5/2025 | 17/6/2026 | The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.27% | — | Mpl-publisher | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= 2.18.0. | |
| Analizada | Alta (7.2) | 0.50% | — | Litepublisher Litepubl CMS | 17/4/2025 | 17/6/2026 | Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run. | |
| Analizada | Alta (7.5) | 0.43% | — | Oracle BI Publisher | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this… | |
| Analizada | Media (5.4) | 0.33% | — | Oracle BI Publisher | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this… | |
| Aplazada | Media (5.4) | 0.32% | — | Contentmx Content PublisherAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in ContentMX ContentMX Content Publisher contentmx-content-publisher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ContentMX Content Publisher: from n/a through <= 1.0.6. | |
| Aplazada | Media (4.3) | 0.14% | — | Nopeamedia Print PDF Generator AND PublisherAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Cross Site Request Forgery.This issue affects Print PDF Generator and Publisher: from n/a through <= 1.2.0. | |
| Analizada | Media (4.3) | 0.22% | — | Podlove Podcast Publisher | 6/3/2025 | 17/6/2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the ajax_transcript_delete() function. This makes it possible for unauthenticated attackers to delete arbitrary episode… | |
| Aplazada | Alta (8.5) | 0.81% | — | Flexnet PublisherAIOpensslAI | 30/1/2025 | 17/6/2026 | A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file… | |
| Aplazada | Media (4.2) | 0.18% | — | HL7 Fhir IG PublisherAI | 24/1/2025 | 17/6/2026 | The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.8.9, in CI contexts, the IG Publisher CLI uses git commands to determine the URL of the originating repo. If the repo was cloned, or otherwise set to use a repo that uses a username and credential based URL,… | |
| Aplazada | Alta (8.6) | 0.56% | — | HL7 Fhir IG PublisherAI | 24/1/2025 | 17/6/2026 | The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag `( ]>` could produce XML containing data from the host… | |
| Analizada | Media (4) | 0.27% | — | Podlove Podcast Publisher | 18/1/2025 | 17/6/2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.17% | — | Cdowp News Publisher AutopilotAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cdowp News Publisher Autopilot wpm-news-api allows Cross Site Request Forgery.This issue affects News Publisher Autopilot: from n/a through <= 2.1.4. | |
| Aplazada | Media (6.1) | 0.36% | — | Bitcoin Lightning PublisherAI | 24/12/2024 | 17/6/2026 | The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.5) | 0.23% | — | Nopeamedia Print PDF Generator AND PublisherAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Stored XSS.This issue affects Print PDF Generator and Publisher: from n/a through <= 1.1.6. | |
| Modificada | Alta (7.2) | 0.53% | — | Podlove Podcast Publisher | 14/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15. | |
| Analizada | Alta (8.8) | 0.31% | — | Podlove Podcast Publisher | 31/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13. | |
| Analizada | Alta (8.8) | 0.52% | — | Oracle BI Publisher | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks… | |
| Modificada | Alta (7.6) | 0.44% | — | Oracle BI Publisher | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful… | |
| Analizada | Media (5.4) | 0.29% | — | Podlove Podcast Publisher | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13. |