Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant MenuAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | |
| Aplazada | Alta (8.1) | 0.35% | — | Royal Plugins Royal MCPAI | 25/6/2026 | 25/6/2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Weplugins WP MapsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | |
| Pendiente de análisis | Alta (7.6) | 0.70% | — | Gstreamer Gst-plugins-goodAI | 15/6/2026 | 3/8/2026 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 8/9/2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 5/8/2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel… | |
| Pendiente de análisis | Alta (7.1) | 0.63% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing… | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1… | |
| Aplazada | Media (6.4) | 0.33% | — | Fooplugins FoogalleryAI | 13/6/2026 | 23/7/2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of… | |
| Pendiente de análisis | Media (6.5) | 0.40% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three… | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 9/6/2026 | 28/8/2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 9/6/2026 | 28/8/2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (4.3) | 0.26% | — | Weplugins User FrontendAI | 9/6/2026 | 23/7/2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it… | |
| Aplazada | Media (4.4) | 0.33% | — | Weplugins WP MapsAI | 6/6/2026 | 23/7/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.5) | 0.43% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14. | |
| Aplazada | Alta (7.5) | 0.39% | — | Really-simple-plugins Really Simple SecurityAI | 2/6/2026 | 22/7/2026 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. | |
| Analizada | Media (5.1) | 0.39% | — | TFA Basic Plugins Project TFA Basic Plugins | 28/5/2026 | 21/7/2026 | An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Oplugins Booking ManagerAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18. | |
| Aplazada | Alta (7.1) | 0.25% | — | HT Plugins HT Contact Form 7AI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2. | |
| Aplazada | Media (4.3) | 0.15% | — | Bplugins Tiktok FeedAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24. | |
| Aplazada | Alta (7.5) | 0.39% | — | Plainviewplugins MycryptocheckoutAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161. | |
| Aplazada | Media (6.5) | 0.17% | — | Pickplugins Team ShowcaseAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28. | |
| Aplazada | Alta (7.5) | 0.47% | — | Weplugins WP MapsAI | 18/5/2026 | 17/6/2026 | The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks. |