Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

814 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.29%—Masteriyo - LMSAI23/7/202623/7/2026
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
AplazadaAlta (8.5)0.36%—Quizandsurveymaster Quiz AND Survey MasterAI23/7/202623/7/2026
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
AplazadaMedia (6.5)0.22%—Masteriyo LMSAI23/7/202623/7/2026
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
AplazadaMedia (6.5)0.41%—Quiz Master NextAI16/7/202616/7/2026
The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient…
AplazadaBaja (1.9)0.17%—Mastergo Magic MCPAI14/7/202615/7/2026
A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the component mcp__getComponentGenerator. The manipulation of the argument rootPath leads to path traversal. An attack has to be…
AplazadaBaja (2.1)0.40%—Mastergo-design Mastergo-magic-mcpAI14/7/202615/7/2026
A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from…
AplazadaBaja (1.9)0.17%—Mastergo-design Mastergo-magic-mcpAI14/7/202615/7/2026
A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component mcp__C2d. Performing a manipulation of the argument filePath results in path traversal. The attack requires a local approach. The exploit has…
AplazadaBaja (1.9)0.15%—Qiling Disk MasterAI12/7/202613/7/2026
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local environment. The exploit has been…
AplazadaAlta (8.4)0.13%—Qualcomm Fabrickeymaster TrustletAI10/7/202611/7/2026
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.
AplazadaMedia (4.3)0.49%—Quizandsurveymaster Quiz AND Survey MasterAI3/7/20266/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaAlta (7.5)0.43%—TourmasterAI2/7/20266/10/2026
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
AplazadaMedia (6.5)0.22%—Masterstudy LMSAI29/6/202629/6/2026
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
AplazadaMedia (4.3)0.47%—Quizandsurveymaster Quiz AND Survey MasterAI27/6/202629/6/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.25%—Masteriyo LMSAI27/6/202629/6/2026
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaMedia (4.3)0.25%—Stylemixthemes Masterstudy LMSAI26/6/202626/6/2026
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
AplazadaAlta (7.1)0.25%—Masterslider Master SliderAI25/6/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider master-slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.11.3.
AplazadaMedia (6.5)0.27%—Masteriyo LMSAI25/6/202625/6/2026
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.
Pendiente de análisisMedia (4.1)0.12%—ABB Control Builder AAIABB 800xa FOR Advant MasterAI23/6/20266/10/2026
Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.
AplazadaAlta (7.1)0.16%—Easeus Partition MasterAI21/6/202623/6/2026
A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and…
AplazadaAlta (7.1)0.16%—Easeus Partition MasterAI21/6/202622/6/2026
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be…
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
AplazadaMedia (6.5)0.20%—Masteriyo - LMSAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
AplazadaAlta (8.5)0.36%—Masterstudy LMSAI15/6/202617/6/2026
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
AplazadaAlta (7.5)0.35%—Masteriyo - LMSAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.