Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.26% | — | Dotcamp Ultimate Blocks | 10/6/2025 | 17/6/2026 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (8.1) | 0.22% | — | DOTAI | 2/6/2025 | 17/6/2026 | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | |
| Analizada | Crítica (9.1) | 0.46% | — | Ingydotnet Yaml-libyaml | 1/6/2025 | 17/6/2026 | YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified | |
| Analizada | Media (6.1) | 0.28% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. | |
| Analizada | Media (6) | 0.23% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Version 9.13.9 fixes the issue. | |
| Analizada | Baja (2.4) | 0.24% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue. | |
| Aplazada | Alta (7.1) | 0.22% | — | Fyrewurks Polka DotsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks polka dots allows Reflected XSS.This issue affects polka dots: from n/a through 1.2. | |
| Aplazada | Media (6.5) | 0.29% | — | Dotcamp Ultimate BlocksAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows DOM-Based XSS.This issue affects Ultimate Blocks: from n/a through <= 3.3.0. | |
| Aplazada | Alta (7.1) | 0.22% | — | Karimmughal DOT Html PHP XML ETC PagesAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages dot-htmlphpxml-etc-pages allows Reflected XSS.This issue affects Dot html,php,xml etc pages: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.30% | — | Dotcamp Ultimate BlocksAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows DOM-Based XSS.This issue affects Ultimate Blocks: from n/a through <= 3.2.9. | |
| Modificada | Crítica (9.8) | 0.32% | — | Multidots Advanced Linked Variations FOR Woocommerce | 22/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Linked Variations for Woocommerce: from n/a through <= 1.0.3. | |
| Aplazada | Alta (8.7) | 0.61% | — | Amazon ION DotnetAI | 21/4/2025 | 17/6/2026 | When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, this triggers an infinite loop condition that could potentially… | |
| Analizada | Alta (7.5) | 0.39% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8. | |
| Analizada | Media (6.5) | 0.38% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8. | |
| Analizada | Alta (7.5) | 0.37% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent… | |
| Analizada | Media (4.3) | 0.29% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image and a user that trusts the domain might think that the information is… | |
| Analizada | Media (6.5) | 0.30% | — | Dnnsoftware Dotnetnuke | 8/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic… | |
| Analizada | Alta (7.5) | 0.18% | — | Dnnsoftware Dotnetnuke | 8/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's… | |
| Aplazada | Alta (7.3) | 0.33% | — | Philips Intellispace PortalAIMicrosoft DotnetAI | 7/4/2025 | 17/6/2026 | The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can… | |
| Aplazada | Media (6.5) | 0.40% | — | Piotnetdotcom Piotnet Addons FOR ElementorAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Addons For Elementor piotnet-addons-for-elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through <= 2.4.36. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Shopperdotcom ShopperAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shopper shopper allows SQL Injection.This issue affects Shopper: from n/a through <= 3.2.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Dotcamp Ultimate BlocksAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows DOM-Based XSS.This issue affects Ultimate Blocks: from n/a through <= 3.2.7. | |
| Aplazada | Media (6.4) | 0.32% | — | Dotcamp Ultimate BlocksAI | 26/3/2025 | 17/6/2026 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttonTextColor’ parameter in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.51% | — | Opentelemetry DotnetAI | 5/3/2025 | 17/6/2026 | OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still… | |
| Aplazada | Alta (7.1) | 0.39% | — | Dotsquaresltd Migrate PostsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DotsquaresLtd Migrate Posts migrate-post allows Reflected XSS.This issue affects Migrate Posts: from n/a through <= 1.0. |