Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1458 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.18%—Miniorange Google AuthenticatorAI6/8/202626/8/2026
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.
AplazadaAlta (7.5)0.43%—Miniorange 2FAAI5/8/202626/8/2026
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the…
AplazadaMedia (4.3)0.33%—Miniorange 2FAAI4/8/202626/8/2026
The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP…
AplazadaMedia (6.2)0.19%—Gemini-bridgeAI31/7/202610/9/2026
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI.…
AplazadaAlta (8.8)0.21%—Prestashop TotadministrativemandateAI31/7/202631/8/2026
PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link.
AplazadaAlta (8.1)0.29%—Miniorange 2FAAI31/7/202626/8/2026
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access…
AplazadaAlta (8.1)0.38%—Miniorange Social Login AND RegisterAI29/7/202630/7/2026
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any…
AplazadaAlta (7.1)0.25%—Miniorange OTP VerificationAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Pendiente de análisisCrítica (9.8)1.9%—Miniorange Saml Single Sign ONAI23/7/202624/7/2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return…
AplazadaAlta (8.1)0.46%—Miniorange Discord IntegrationAI23/7/202623/7/2026
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
Pendiente de análisisBaja (3.3)0.13%—Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI22/7/202622/7/2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's…
AplazadaBaja (1.3)1.5%—Qusetions Minicode-pythonAI22/7/202622/7/2026
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is…
AplazadaBaja (1.3)1.2%—Liumenxuan04 MinicodeAI18/7/202620/7/2026
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be…
AplazadaCrítica (9.8)1.5%—Miniorange Saml Single Sign ON SSOAI16/7/20267/8/2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the…
AplazadaAlta (8.7)0.36%—Luci-app-upnpAIMiniupnpdAI12/7/202630/9/2026
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding,…
AplazadaBaja (1.9)0.15%—Minitool Partition WizardAI12/7/202613/7/2026
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the…
AplazadaCrítica (9.8)0.73%—Miniorange Oauth Single Sign ON - SSOAI10/7/202621/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
AplazadaCrítica (9.8)0.89%—Miniorange Social Login AND RegisterAI10/7/202613/7/2026
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST…
AplazadaCrítica (9.8)1.1%—Miniorange OTP Login Verification AND SMS NotificationsAI9/7/20269/7/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the…
AplazadaBaja (2.7)0.32%—AdminifyAI2/7/20262/7/2026
The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by one of its administration search features, allowing users with a low-privilege role (Contributor) to disclose non-public content that WordPress would not otherwise expose to them, such as other…
AplazadaAlta (7.5)0.49%—Javascript Minifier XSAI29/6/202630/6/2026
JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. The regexp versus division disambiguator in JsTokenizeString (XS.xs) inspects the previous token's last byte to choose between a regexp literal and a division operator.…
AplazadaMedia (6.5)0.29%—CSS Minifier XSAI29/6/202630/6/2026
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and whitespace.
AplazadaAlta (7.6)0.38%—AdministratorAI26/6/202626/6/2026
Administrator SQL Injection in Popup box <= 6.0.1 versions.
AplazadaMedia (6.5)0.37%—Geminilabs Site ReviewsAI26/6/202626/6/2026
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
AnalizadaCrítica (10)0.21%—Google Gemini-cliGoogle Run-gemini-cli24/6/20262/7/2026
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted…