Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Fivestarplugins Five Star Restaurant MenuAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
AplazadaAlta (8.1)0.35%—Royal Plugins Royal MCPAI25/6/202625/6/2026
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.
AplazadaAlta (7.5)0.35%—Fivestarplugins Five Star Restaurant ReservationsAI25/6/202629/6/2026
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
AplazadaCrítica (9.3)0.40%—Weplugins WP MapsAI15/6/202617/6/2026
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
Pendiente de análisisAlta (7.6)0.70%—Gstreamer Gst-plugins-goodAI15/6/20263/8/2026
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded…
Pendiente de análisisAlta (7.1)0.46%—Gstreamer Gst-plugins-uglyAI15/6/20268/9/2026
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped…
Pendiente de análisisAlta (7.1)0.46%—Gstreamer Gst-plugins-uglyAI15/6/20265/8/2026
A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel…
Pendiente de análisisAlta (7.1)0.63%—Gstreamer Gst-plugins-badAI15/6/202630/7/2026
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing…
Pendiente de análisisMedia (6.5)0.71%—Gstreamer Gst-plugins-badAI15/6/202630/7/2026
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1…
AplazadaMedia (6.4)0.33%—Fooplugins FoogalleryAI13/6/202623/7/2026
The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of…
Pendiente de análisisMedia (6.5)0.40%—Gstreamer Gst-plugins-badAI11/6/202617/6/2026
A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence…
Pendiente de análisisMedia (6.5)0.37%—Gstreamer Gst-plugins-badAI11/6/202617/6/2026
An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three…
AnalizadaAlta (7.8)0.34%—Adobe Format Plugins9/6/202628/8/2026
Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.34%—Adobe Format Plugins9/6/202628/8/2026
Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaMedia (4.3)0.26%—Weplugins User FrontendAI9/6/202623/7/2026
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it…
AplazadaMedia (4.4)0.33%—Weplugins WP MapsAI6/6/202623/7/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (7.5)0.43%—Fivestarplugins Five Star Restaurant ReservationsAI2/6/202622/7/2026
Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.
AplazadaAlta (7.5)0.39%—Really-simple-plugins Really Simple SecurityAI2/6/202622/7/2026
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge.
AnalizadaMedia (5.1)0.39%—TFA Basic Plugins Project TFA Basic Plugins28/5/202621/7/2026
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
AplazadaMedia (6.5)0.22%—Oplugins Booking ManagerAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18.
AplazadaAlta (7.1)0.25%—HT Plugins HT Contact Form 7AI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2.
AplazadaMedia (4.3)0.15%—Bplugins Tiktok FeedAI26/5/202624/7/2026
Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24.
AplazadaAlta (7.5)0.39%—Plainviewplugins MycryptocheckoutAI25/5/202624/7/2026
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.
AplazadaMedia (6.5)0.17%—Pickplugins Team ShowcaseAI25/5/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28.
AplazadaAlta (7.5)0.47%—Weplugins WP MapsAI18/5/202617/6/2026
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.