Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.54% | — | Ipages Flipbook Project Ipages Flipbook | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8. | |
| Modificada | Media (4.3) | 0.38% | — | Flippercode Wp-security-questions | 1/7/2023 | 17/6/2026 | The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request… | |
| Modificada | Media (6.1) | 0.41% | — | Oxilab Image Hover Effects FOR Elementor With Lightbox AND Flipbox | 28/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Winwar WP Flipclock | 23/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Flipclock plugin <= 1.7.4 versions. | |
| Modificada | Media (5.4) | 0.53% | — | 3dflipbook 3D Flipbook | 16/1/2023 | 17/6/2026 | The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators. | |
| Modificada | Media (5.4) | 0.47% | — | Ipages Flipbook Project Ipages Flipbook | 9/1/2023 | 17/6/2026 | The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.5) | 0.35% | 💥 PoC | Flipperzero Flipper Zero Firmware | 29/9/2022 | 17/6/2026 | A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file. | |
| Modificada | Alta (7.2) | 1.3% | — | Oxilab Flipbox | 25/7/2022 | 17/6/2026 | Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress. | |
| Modificada | Media (5.4) | 0.60% | — | 3dflipbook 3D Flipbook | 21/3/2022 | 17/6/2026 | The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook. | |
| Modificada | Media (5.4) | 0.65% | — | Dearhive Dearflip | 18/10/2021 | 17/6/2026 | The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.5) | 1.5% | — | Flippy Project Flippy | 30/1/2020 | 16/6/2026 | The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node. | |
| Modificada | Media (6.1) | 0.75% | — | Alcatelmobile Cingular Flip 2 Firmware | 26/11/2019 | 17/6/2026 | On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware… | |
| Modificada | Media (6.8) | 1.1% | — | Alcatelmobile Cingular Flip 2 Firmware | 26/11/2019 | 17/6/2026 | On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary OS commands as the root user via the application's UI. | |
| Modificada | Media (6.8) | 0.48% | — | Alcatelmobile Cingular Flip 2 Firmware | 26/11/2019 | 17/6/2026 | On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock screen checks for the existence of a specific file and disables PIN authentication if it exists. This file would typically… | |
| Modificada | Media (6.1) | 1.0% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload. | |
| Modificada | Alta (7.5) | 2.2% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. | |
| Modificada | Crítica (9.8) | 2.3% | — | Flippa Marketplace Clone Project Flippa Marketplace Clone | 19/6/2019 | 17/6/2026 | SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter. | |
| Modificada | Crítica (9.8) | 4.4% | — | Page Flip Book Project Page Flip Book | 13/5/2019 | 16/6/2026 | Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Visiology Flipbox | 27/8/2018 | 17/6/2026 | Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters. | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Media (5.9) | 5.5% | — | Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+7 | 16/5/2018 | 17/6/2026 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a… | |
| Modificada | Media (5.4) | 0.81% | — | Flippercode WP Google MAP | 14/5/2018 | 17/6/2026 | Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 0.77% | — | Flipbuilder Flip PDF | 1/6/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF allows remote attackers to inject arbitrary web script or HTML via the currentHTMLURL parameter. | |
| Modificada | Media (5.4) | 0.29% | — | Threadflip BUY Sell Fashion | 22/9/2014 | 17/6/2026 | The Threadflip : Buy, Sell Fashion (aka com.threadflip.android) application 1.1.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |