Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

6912 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.75%—Junrar Project Junrar26/2/202617/6/2026
Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often…
AnalizadaAlta (8.8)2.1%—Super-linter Project Super-linter9/2/202617/6/2026
Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull request that introduces…
AnalizadaMedia (6.3)0.40%—Htmlsanitizer Project Htmlsanitizer4/2/202617/6/2026
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the…
AplazadaMedia (4.9)0.69%—Zephyr Project ManagerAI17/12/202528/9/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain…
ModificadaAlta (7.7)0.52%💥 PoCValidator Project Validator27/11/202514/7/2026
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This…
AplazadaCrítica (9.8)0.47%—S2member Project S2memberAI6/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701.
AnalizadaMedia (5.3)0.30%—Reverse Proxy Header Project Reverse Proxy Header30/10/202517/6/2026
Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.
AnalizadaMedia (5.3)0.25%—API KEY Manager Project API KEY Manager10/10/202517/6/2026
Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.
ModificadaMedia (6.1)0.32%—Validator Project Validator30/9/20255/7/2026
A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open…
AplazadaMedia (4.4)0.20%—Zephyr Project ManagerAI26/9/202517/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AnalizadaBaja (1.9)0.27%—Voice Changer Project Voice Changer29/8/202517/6/2026
A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack on the local…
AplazadaAlta (7.1)0.22%—Dylan James Zephyr Project ManagerAI28/8/202525/9/2026
Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201.
AnalizadaCrítica (9.3)1.6%💥 ExploitEasyftp Server Project Easyftp Server21/8/202516/6/2026
EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially…
AnalizadaCrítica (9.3)3.2%💥 ExploitEasyftp Server Project Easyftp Server21/8/202516/6/2026
EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the FTP command parser. When processing the CWD (Change Working Directory) command, the server fails to properly validate the length of the input string, allowing attackers to overwrite memory on the stack. This flaw enables…
AnalizadaAlta (8.8)0.26%—AI SEO Link Advisor Project AI SEO Link Advisor15/8/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from 0.0.0 before 1.0.6.
AnalizadaMedia (6.1)0.23%—Googletag Manager Project Googletag Manager15/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag Manager allows Cross-Site Scripting (XSS).This issue affects GoogleTag Manager: from 0.0.0 before 1.10.0.
AnalizadaBaja (1.9)0.23%—Jasper Project Jasper11/8/202517/6/2026
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.…
AnalizadaBaja (1.9)0.21%—Jasper Project Jasper11/8/202517/6/2026
A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation leads to reachable assertion. The attack needs to be approached locally. The exploit has been disclosed to the public…
AnalizadaBaja (1.9)0.22%—Jasper Project Jasper11/8/202517/6/2026
A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host.…
AnalizadaCrítica (9.8)7.8%💥 ExploitWP Mobile Detector Project WP Mobile Detector19/7/202517/6/2026
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code…
AnalizadaMedia (5.3)0.30%—Config Pages Viewer Project Config Pages Viewer8/7/202517/6/2026
Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.
AnalizadaMedia (4.3)0.14%—VR Calendar Project VR Calendar27/6/202517/6/2026
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted…
AnalizadaAlta (7.2)0.94%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary…
AnalizadaMedia (4.9)0.42%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access…
ModificadaMedia (6.1)0.27%—Iframe Remove Filter Project Iframe Remove Filter14/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 2.0.0 before 2.0.5, from 7.X-1.0 through 7.X-1.5, from 1.0 through 1.2.