Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
814 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.29% | — | Masteriyo - LMSAI | 23/7/2026 | 23/7/2026 | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Masteriyo LMSAI | 23/7/2026 | 23/7/2026 | Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | |
| Aplazada | Media (6.5) | 0.41% | — | Quiz Master NextAI | 16/7/2026 | 16/7/2026 | The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo Magic MCPAI | 14/7/2026 | 15/7/2026 | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the component mcp__getComponentGenerator. The manipulation of the argument rootPath leads to path traversal. An attack has to be… | |
| Aplazada | Baja (2.1) | 0.40% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component mcp__C2d. Performing a manipulation of the argument filePath results in path traversal. The attack requires a local approach. The exploit has… | |
| Aplazada | Baja (1.9) | 0.15% | — | Qiling Disk MasterAI | 12/7/2026 | 13/7/2026 | A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local environment. The exploit has been… | |
| Aplazada | Alta (8.4) | 0.13% | — | Qualcomm Fabrickeymaster TrustletAI | 10/7/2026 | 11/7/2026 | Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code. | |
| Aplazada | Media (4.3) | 0.49% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 3/7/2026 | 6/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.5) | 0.43% | — | TourmasterAI | 2/7/2026 | 6/10/2026 | Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Masterstudy LMSAI | 29/6/2026 | 29/6/2026 | Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions. | |
| Aplazada | Media (4.3) | 0.47% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/6/2026 | 29/6/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.25% | — | Masteriyo LMSAI | 27/6/2026 | 29/6/2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.25% | — | Stylemixthemes Masterstudy LMSAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Masterslider Master SliderAI | 25/6/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider master-slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.11.3. | |
| Aplazada | Media (6.5) | 0.27% | — | Masteriyo LMSAI | 25/6/2026 | 25/6/2026 | The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records. | |
| Pendiente de análisis | Media (4.1) | 0.12% | — | ABB Control Builder AAIABB 800xa FOR Advant MasterAI | 23/6/2026 | 6/10/2026 | Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1. | |
| Aplazada | Alta (7.1) | 0.16% | — | Easeus Partition MasterAI | 21/6/2026 | 23/6/2026 | A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and… | |
| Aplazada | Alta (7.1) | 0.16% | — | Easeus Partition MasterAI | 21/6/2026 | 22/6/2026 | A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be… | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions. | |
| Aplazada | Media (6.5) | 0.20% | — | Masteriyo - LMSAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Masterstudy LMSAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Masteriyo - LMSAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions. |