Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

120 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.54%—Ipages Flipbook Project Ipages Flipbook20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.
ModificadaMedia (4.3)0.38%—Flippercode Wp-security-questions1/7/202317/6/2026
The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request…
ModificadaMedia (6.1)0.41%—Oxilab Image Hover Effects FOR Elementor With Lightbox AND Flipbox28/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
ModificadaMedia (5.4)0.39%—Winwar WP Flipclock23/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Flipclock plugin <= 1.7.4 versions.
ModificadaMedia (5.4)0.53%—3dflipbook 3D Flipbook16/1/202317/6/2026
The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.
ModificadaMedia (5.4)0.47%—Ipages Flipbook Project Ipages Flipbook9/1/202317/6/2026
The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.5)0.35%💥 PoCFlipperzero Flipper Zero Firmware29/9/202217/6/2026
A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.
ModificadaAlta (7.2)1.3%—Oxilab Flipbox25/7/202217/6/2026
Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.
ModificadaMedia (5.4)0.60%—3dflipbook 3D Flipbook21/3/202217/6/2026
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.
ModificadaMedia (5.4)0.65%—Dearhive Dearflip18/10/202117/6/2026
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.5)1.5%—Flippy Project Flippy30/1/202016/6/2026
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.
ModificadaMedia (6.1)0.75%—Alcatelmobile Cingular Flip 2 Firmware26/11/201917/6/2026
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware…
ModificadaMedia (6.8)1.1%—Alcatelmobile Cingular Flip 2 Firmware26/11/201917/6/2026
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary OS commands as the root user via the application's UI.
ModificadaMedia (6.8)0.48%—Alcatelmobile Cingular Flip 2 Firmware26/11/201917/6/2026
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock screen checks for the existence of a specific file and disables PIN authentication if it exists. This file would typically…
ModificadaMedia (6.1)1.0%—Creativeinteractivemedia Real3d Flipbook16/9/201917/6/2026
The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter.
ModificadaAlta (7.5)2.6%—Creativeinteractivemedia Real3d Flipbook16/9/201917/6/2026
The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
ModificadaAlta (7.5)2.2%—Creativeinteractivemedia Real3d Flipbook16/9/201917/6/2026
The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
ModificadaCrítica (9.8)2.3%—Flippa Marketplace Clone Project Flippa Marketplace Clone19/6/201917/6/2026
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
ModificadaCrítica (9.8)4.4%—Page Flip Book Project Page Flip Book13/5/201916/6/2026
Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.
ModificadaAlta (7.5)1.8%—Visiology Flipbox27/8/201817/6/2026
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
ModificadaMedia (5.9)4.1%—9folders NineApple MailBloop AirmailEmclient+1316/5/201817/6/2026
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
ModificadaMedia (5.9)5.5%—Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+716/5/201817/6/2026
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a…
ModificadaMedia (5.4)0.81%—Flippercode WP Google MAP14/5/201817/6/2026
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)0.77%—Flipbuilder Flip PDF1/6/201717/6/2026
Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF allows remote attackers to inject arbitrary web script or HTML via the currentHTMLURL parameter.
ModificadaMedia (5.4)0.29%—Threadflip BUY Sell Fashion22/9/201417/6/2026
The Threadflip : Buy, Sell Fashion (aka com.threadflip.android) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades