Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.74%—Hexoeditor Project Hexoeditor21/3/202217/6/2026
HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times.
AnalizadaMedia (5.5)0.73%—Metadata-extractor Project Metadata-extractor24/2/202217/6/2026
When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.
AnalizadaMedia (5.5)0.78%—Metadata-extractor Project Metadata-extractor24/2/202217/6/2026
metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.
ModificadaMedia (6.1)0.76%—H5p-css-editor Project H5p-css-editor14/12/202117/6/2026
The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.
ModificadaMedia (4.8)0.62%—Inspirational Quote Rotator Project Inspirational Quote Rotator13/12/202117/6/2026
The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.62%—QR Redirector Project QR Redirector17/11/202117/6/2026
The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.
ModificadaMedia (4.3)0.45%—QR Redirector Project QR Redirector17/11/202117/6/2026
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects
ModificadaAlta (7.5)1.1%—Fort Validator Project Fort ValidatorDebian Linux9/11/202117/6/2026
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
ModificadaAlta (7.5)1.8%—Validator Project Validator2/11/202117/6/2026
validator.js is vulnerable to Inefficient Regular Expression Complexity
ModificadaMedia (6.1)0.73%—Detector Project Detector1/10/202117/6/2026
Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
ModificadaAlta (7.5)2.5%—Openvpn-monitor Project Openvpn-monitor27/9/202117/6/2026
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
ModificadaAlta (7.5)3.3%—Openvpn-monitor Project Openvpn-monitor27/9/202117/6/2026
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
ModificadaMedia (6.5)0.68%—Openvpn-monitor Project Openvpn-monitor27/9/202117/6/2026
furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
ModificadaMedia (5.4)0.62%—Custom Post View Generator Project Custom Post View Generator13/9/202117/6/2026
The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue
ModificadaMedia (5.4)0.62%—Business Hours Indicator Project Business Hours Indicator30/8/202117/6/2026
The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
ModificadaMedia (5.9)1.1%—Generator Project Generator8/8/202117/6/2026
An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.
ModificadaMedia (5.9)0.98%—Disrustor Project Disrustor8/8/202117/6/2026
An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references.
ModificadaMedia (6.1)0.67%—Cgm-remote-monitor Project Cgm-remote-monitor16/7/202117/6/2026
Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header.
ModificadaMedia (5.4)0.62%—WP Config File Editor Project WP Config File Editor21/6/202117/6/2026
The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (XSS) vulnerability.
ModificadaCrítica (9.8)1.3%—Ps-visitor Project Ps-visitor18/4/202117/6/2026
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
ModificadaMedia (5.4)0.69%—Testimonial Rotator Project Testimonial Rotator5/4/202117/6/2026
Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation
ModificadaAlta (7.3)1.0%—Stackvector Project Stackvector1/4/202117/6/2026
An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVec::extend if size_hint provides certain anomalous data.
ModificadaAlta (7.5)2.1%—Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight19/3/202117/6/2026
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example…
ModificadaAlta (7.5)1.8%—Djvalidator Project Djvalidator26/11/202017/6/2026
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.
ModificadaMedia (5.4)0.72%—Testimonial Rotator Project Testimonial Rotator16/10/202017/6/2026
Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database.
Orbitaley — Vulnerabilidades