Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.23% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters. | |
| Analizada | Media (5.3) | 0.22% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination. | |
| Analizada | Alta (7.1) | 0.52% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken,… | |
| Aplazada | Media (6.8) | 0.22% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store… | |
| Aplazada | Media (6.8) | 0.29% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for… | |
| Aplazada | Crítica (9.8) | 0.75% | — | ZlmediakitAI | 21/9/2026 | 24/9/2026 | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are… | |
| Aplazada | Media (6) | 0.41% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. An authenticated user… | |
| Aplazada | Alta (8.1) | 0.45% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's… | |
| Aplazada | Media (5.4) | 0.29% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through… | |
| Pendiente de análisis | Media (6.1) | 0.33% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added in 7.0.0). The token is decoded by `CursorEncoder`, which is an **unsigned**… | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | MediawikiAISemantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`) is assembled by `SMW\Query\DebugFormatter` and emitted as raw HTML. Several of… | |
| Pendiente de análisis | Media (6.1) | 0.25% | — | MediawikiAISemantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and issues an HTTP 303 redirect to `$title->getFullURL()` without validating the… | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 23/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value. Version 7.2.0 fixes the issue. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version… | |
| Pendiente de análisis | Alta (8.6) | 0.29% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue. | |
| Aplazada | Alta (7.5) | 0.49% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON… | |
| Aplazada | Alta (8.6) | 0.48% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | Mediawiki ProofreadpageAI | 14/9/2026 | 16/9/2026 | An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables. | |
| Pendiente de análisis | Media (5.4) | 0.21% | — | Mediawiki MassmessageAIMediawikiAI | 14/9/2026 | 28/9/2026 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS. | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | Mediawiki CheckuserAIMediawikiAI | 14/9/2026 | 16/9/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden. | |
| Aplazada | Media (4.2) | 0.19% | — | Rtcamp RtmediaAI | 13/9/2026 | 14/9/2026 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's… | |
| Aplazada | Alta (7.5) | 0.34% | — | Rtcamp RtmediaAI | 12/9/2026 | 15/9/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… |