Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

232 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.22%—Redboltz Async Mqtt24/11/202517/6/2026
Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.
AnalizadaBaja (2.9)0.22%—Authzed Spicedb21/11/202517/6/2026
SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a…
AplazadaMedia (4.3)0.13%—Syedbalkhi Giveaways AND Contests BY RafflepressAI21/11/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.
AnalizadaBaja (2.7)0.25%—Authzed Spicedb10/11/202517/6/2026
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema; have configured their SpiceDB server such that `--write-relationships-max-updates-per-call` is bigger…
AplazadaMedia (5.3)0.26%—User FeedbackAI25/10/202517/6/2026
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `maybe_load_onboarding_wizard` function in all versions up to, and including, 1.8.0. This makes it possible for…
AplazadaAlta (8.8)0.38%—Bplugins Voice FeedbackAI22/10/202517/6/2026
Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3.
AplazadaMedia (5.4)0.27%—Syedbalkhi ALL IN ONE SEO PackAI22/9/202517/6/2026
Missing Authorization vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All In One SEO Pack: from n/a through <= 4.8.7.1.
AplazadaMedia (6.5)0.20%—Syedbalkhi Compact ArchivesAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Compact Archives compact-archives allows Stored XSS.This issue affects Compact Archives: from n/a through <= 4.1.0.
AplazadaMedia (5.9)0.30%—Syedbalkhi Affiliatewp External Referral LinksAI22/9/20251/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi AffiliateWP – External Referral Links affiliatewp-external-referral-links allows Stored XSS.This issue affects AffiliateWP – External Referral Links: from n/a through <= 1.2.0.
AplazadaMedia (5.1)0.23%—Yugabytedb AnywhereAI11/8/202517/6/2026
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.
AplazadaMedia (4.1)0.16%—YugabytedbAI11/8/202517/6/2026
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.
AplazadaAlta (7)0.24%—YugabytedbAI11/8/202517/6/2026
YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
AplazadaAlta (7)0.34%—YugabytedbAI11/8/202517/6/2026
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.
AnalizadaMedia (6.3)0.25%—Syedbalkhi WP Lightbox 230/6/202517/6/2026
The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.
AplazadaMedia (5.3)0.31%—Syedbalkhi Giveaways AND Contests BY RafflepressAI20/6/202517/6/2026
Missing Authorization vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.18.
AnalizadaMedia (5.3)0.32%—Authzed Spicedb6/6/202517/6/2026
SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a…
AplazadaMedia (5.3)0.31%—EDB PglogicalAIEDB BDRAIEDB PGDAI22/5/202517/6/2026
When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read access to replicated tables. When pglogical runs it should verify it is running on a…
AnalizadaAlta (7.5)1.8%—Microsoft Msagsfeedback.azurewebsites.net8/5/202517/6/2026
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (4.3)0.17%—Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cross Site Request Forgery.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.8.
AplazadaMedia (5.9)0.27%—Syedbalkhi Floating Social BARAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Floating Social Bar floating-social-bar allows Stored XSS.This issue affects Floating Social Bar: from n/a through <= 1.1.7.
AplazadaAlta (7.1)0.29%—Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Reflected XSS.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.7.
AplazadaMedia (5.3)0.55%—J. Tyler Wiest Jetpack Feedback ExporterAI4/4/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedback Exporter jetpack-feedback-exporter allows Retrieve Embedded Sensitive Data.This issue affects Jetpack Feedback Exporter: from n/a through <= 1.23.
AplazadaMedia (5.4)0.16%—FeedbucketAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Feedbucket Feedbucket – Website Feedback Tool feedbucket allows Cross Site Request Forgery.This issue affects Feedbucket – Website Feedback Tool: from n/a through <= 1.0.6.
AplazadaMedia (6.5)0.36%—Arni Cinco Subscription Form FOR FeedblitzAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arni Cinco Subscription Form for Feedblitz feedblitz-email-subscription allows Stored XSS.This issue affects Subscription Form for Feedblitz: from n/a through <= 1.0.9.
AplazadaMedia (6.5)0.36%—Syedbalkhi Simple Post ExpirationAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Simple Post Expiration simple-post-expiration allows DOM-Based XSS.This issue affects Simple Post Expiration: from n/a through <= 1.0.1.
Orbitaley — Vulnerabilidades