Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.33% | — | Bplugins Document EmbedderAI | 5/11/2025 | 17/6/2026 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the… | |
| Analizada | Media (5.3) | 0.26% | — | ARM Mbed TLS | 21/10/2025 | 17/6/2026 | Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. | |
| Analizada | Media (6.2) | 0.22% | — | ARM Mbed TLS | 20/10/2025 | 17/6/2026 | Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd. | |
| Aplazada | Media (5.3) | 0.47% | — | Powerbi Embed ReportsAI | 18/10/2025 | 17/6/2026 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hooked on 'init'. This… | |
| Aplazada | Media (6.8) | 0.46% | 💥 PoC | Dahua Embedded ProductsAI | 15/10/2025 | 17/6/2026 | A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cause tampering with… | |
| Aplazada | Media (6.5) | 0.20% | — | Awsm Embed ANY DocumentAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any Document embed-any-document allows Stored XSS.This issue affects Embed Any Document: from n/a through <= 2.7.7. | |
| Analizada | Media (5.4) | 0.30% | — | Star-citizen Embedvideo | 25/9/2025 | 17/6/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through… | |
| Aplazada | Media (4.3) | 0.14% | — | Tryinteract Interact Quiz EmbedAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tryinteract Interact: Embed A Quiz On Your Site interact-quiz-embed allows Cross Site Request Forgery.This issue affects Interact: Embed A Quiz On Your Site: from n/a through <= 3.1. | |
| Aplazada | Alta (8.8) | 0.86% | — | Embed PDF FOR WpformsAI | 19/9/2025 | 17/6/2026 | The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Aplazada | Media (6.4) | 0.20% | — | Embed Google DatastudioAI | 12/9/2025 | 17/6/2026 | The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.20% | — | Spotify Embed CreatorAI | 12/9/2025 | 30/9/2026 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.9) | 0.33% | — | Lexmark Embedded WEB ServerAI | 9/9/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an attacker to force the device to send an arbitrary HTTP request to a third-party server. Successful exploitation of this vulnerability can lead to… | |
| Aplazada | Media (6.5) | 0.17% | — | Vincent Boiardt Easy Flash EmbedAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Easy Flash Embed easy-flash-embed allows Stored XSS.This issue affects Easy Flash Embed: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Sdewijs Zoomify Embed FOR WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SdeWijs Zoomify embed for WP zoom-image-shortcode allows Stored XSS.This issue affects Zoomify embed for WP: from n/a through <= 1.5.2. | |
| Aplazada | Media (6.4) | 0.25% | — | Embed BokunAI | 16/8/2025 | 17/6/2026 | The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.22% | — | Pareto Digital Embedder FOR Google ReviewsAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Embedder for Google Reviews: from n/a through <= 1.7.3. | |
| Aplazada | Alta (7.5) | 0.34% | — | Embedded-solutions FreemodbusAI | 14/8/2025 | 17/6/2026 | An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via a crafted length value for a packet. | |
| Aplazada | Media (6.5) | 0.21% | — | Perteus Porn Videos EmbedAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perteus Porn Videos Embed porn-videos-embed allows Stored XSS.This issue affects Porn Videos Embed: from n/a through <= 0.9.1. | |
| Aplazada | Media (6.4) | 0.19% | — | Youtube EmbedAI | 29/7/2025 | 17/6/2026 | The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all versions up to, and including, 10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (7.2) | 0.52% | — | Embedthis GoaheadAI | 25/7/2025 | 17/6/2026 | goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter. | |
| Analizada | Baja (3.7) | 0.41% | — | Trustedfirmware Mbed TLS | 20/7/2025 | 17/6/2026 | In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 Exploit | ARM Mbed TLS | 20/7/2025 | 17/6/2026 | Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The documentation does not suggest that the function will free that… | |
| Modificada | Alta (7.5) | 0.50% | — | ARM Mbed TLS | 20/7/2025 | 17/6/2026 | Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero. | |
| Modificada | Media (4.8) | 0.33% | — | ARM Mbed TLS | 4/7/2025 | 17/6/2026 | Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input. | |
| Modificada | Alta (7.8) | 0.21% | — | ARM Mbed TLS | 4/7/2025 | 17/6/2026 | Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. |