Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.22% | — | Redboltz Async Mqtt | 24/11/2025 | 17/6/2026 | Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects. | |
| Analizada | Baja (2.9) | 0.22% | — | Authzed Spicedb | 21/11/2025 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a… | |
| Aplazada | Media (4.3) | 0.13% | — | Syedbalkhi Giveaways AND Contests BY RafflepressAI | 21/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20. | |
| Analizada | Baja (2.7) | 0.25% | — | Authzed Spicedb | 10/11/2025 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema; have configured their SpiceDB server such that `--write-relationships-max-updates-per-call` is bigger… | |
| Aplazada | Media (5.3) | 0.26% | — | User FeedbackAI | 25/10/2025 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including, 1.8.0. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.38% | — | Bplugins Voice FeedbackAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.4) | 0.27% | — | Syedbalkhi ALL IN ONE SEO PackAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All In One SEO Pack: from n/a through <= 4.8.7.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Syedbalkhi Compact ArchivesAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Compact Archives compact-archives allows Stored XSS.This issue affects Compact Archives: from n/a through <= 4.1.0. | |
| Aplazada | Media (5.9) | 0.30% | — | Syedbalkhi Affiliatewp External Referral LinksAI | 22/9/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi AffiliateWP – External Referral Links affiliatewp-external-referral-links allows Stored XSS.This issue affects AffiliateWP – External Referral Links: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.1) | 0.23% | — | Yugabytedb AnywhereAI | 11/8/2025 | 17/6/2026 | YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records. | |
| Aplazada | Media (4.1) | 0.16% | — | YugabytedbAI | 11/8/2025 | 17/6/2026 | The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service. | |
| Aplazada | Alta (7) | 0.24% | — | YugabytedbAI | 11/8/2025 | 17/6/2026 | YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission | |
| Aplazada | Alta (7) | 0.34% | — | YugabytedbAI | 11/8/2025 | 17/6/2026 | YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted. | |
| Analizada | Media (6.3) | 0.25% | — | Syedbalkhi WP Lightbox 2 | 30/6/2025 | 17/6/2026 | The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks. | |
| Aplazada | Media (5.3) | 0.31% | — | Syedbalkhi Giveaways AND Contests BY RafflepressAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.18. | |
| Analizada | Media (5.3) | 0.32% | — | Authzed Spicedb | 6/6/2025 | 17/6/2026 | SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a… | |
| Aplazada | Media (5.3) | 0.31% | — | EDB PglogicalAIEDB BDRAIEDB PGDAI | 22/5/2025 | 17/6/2026 | When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read access to replicated tables. When pglogical runs it should verify it is running on a… | |
| Analizada | Alta (7.5) | 1.8% | — | Microsoft Msagsfeedback.azurewebsites.net | 8/5/2025 | 17/6/2026 | Improper access control in Azure allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (4.3) | 0.17% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cross Site Request Forgery.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.8. | |
| Aplazada | Media (5.9) | 0.27% | — | Syedbalkhi Floating Social BARAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Floating Social Bar floating-social-bar allows Stored XSS.This issue affects Floating Social Bar: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.1) | 0.29% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Reflected XSS.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.7. | |
| Aplazada | Media (5.3) | 0.55% | — | J. Tyler Wiest Jetpack Feedback ExporterAI | 4/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedback Exporter jetpack-feedback-exporter allows Retrieve Embedded Sensitive Data.This issue affects Jetpack Feedback Exporter: from n/a through <= 1.23. | |
| Aplazada | Media (5.4) | 0.16% | — | FeedbucketAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Feedbucket Feedbucket – Website Feedback Tool feedbucket allows Cross Site Request Forgery.This issue affects Feedbucket – Website Feedback Tool: from n/a through <= 1.0.6. | |
| Aplazada | Media (6.5) | 0.36% | — | Arni Cinco Subscription Form FOR FeedblitzAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arni Cinco Subscription Form for Feedblitz feedblitz-email-subscription allows Stored XSS.This issue affects Subscription Form for Feedblitz: from n/a through <= 1.0.9. | |
| Aplazada | Media (6.5) | 0.36% | — | Syedbalkhi Simple Post ExpirationAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Simple Post Expiration simple-post-expiration allows DOM-Based XSS.This issue affects Simple Post Expiration: from n/a through <= 1.0.1. |