Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

6912 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.23%—Cookies Consent Manager Project Cookies Coonsent Manager14/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.
AnalizadaAlta (7.5)0.45%—Dbsyncer Project Dbsyncer5/5/202517/6/2026
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
ModificadaMedia (5.4)0.27%—Dbsyncer Project Dbsyncer5/5/20255/7/2026
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.
AnalizadaAlta (7.3)0.39%—Ueditor Project Ueditor23/4/20251/10/2026
Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
ModificadaMedia (6.1)0.31%—Zephyr-one Zephyr Project Manager17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through <= 3.3.101.
AnalizadaMedia (5.9)0.32%—Google Maps\ Store Locator Project16/4/202517/6/2026
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
AplazadaMedia (5.4)0.35%—Dylan James Zephyr Project ManagerAI16/4/202517/6/2026
Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.200.
AplazadaMedia (6.9)0.23%—Ts-asn1-der Project Ts-asn1-derAI7/4/202517/6/2026
ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding can lead to denial on service for absolute values in the range 2**31 -- 2**32 - 1. The arithmetic in the numBitLen didn't take into account that values in this range could result in a negative result…
AnalizadaCrítica (9.8)0.43%—Oauth2 Server Project Oauth2 Server31/3/202517/6/2026
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.
AnalizadaBaja (3.5)0.26%—Simple Banner Project Simple Banner25/3/202517/6/2026
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaAlta (8.8)0.62%—Umeditor Project Umeditor3/3/202517/6/2026
A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.
AnalizadaBaja (3.8)0.34%—Crelly Slider Project Crelly Slider27/1/202517/6/2026
The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (6.1)0.17%—MDC Youtube Downloader Project MDC Youtube Downloader16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows Stored XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0.
AplazadaMedia (4)0.13%—Notaryproject Notation-goAI13/1/202517/6/2026
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp…
AnalizadaBaja (3.3)0.19%—Notaryproject Notation-go13/1/202517/6/2026
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature. After retrieving the CRL, notation-go attempts to update the…
AnalizadaAlta (8.8)0.20%—Migrate Queue Importer Project Migrate Queue Importer9/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.
AnalizadaCrítica (9.1)0.37%—Swift Mailer Project Swift Mailer9/1/202517/6/2026
Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.
AplazadaAlta (7.5)0.60%—Matter Project ChipAIConnectedhomeipAI18/12/202417/6/2026
In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service.
ModificadaMedia (5.4)0.31%—MDC Youtube Downloader Project MDC Youtube Downloader19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows DOM-Based XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0.
AnalizadaMedia (5.5)0.20%—Linux KernelFedoraproject Fedora14/11/202417/6/2026
A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.
AnalizadaAlta (7.1)0.32%—Dylanjkotze Zephyr Project Manager26/8/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.
AnalizadaMedia (5.4)0.26%—Zephyr-one Zephyr Project Manager26/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
AnalizadaCrítica (9.8)0.37%—Zephyr-one Zephyr Project Manager18/8/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
AnalizadaAlta (8.1)0.40%—Zephyr-one Zephyr Project Manager15/8/202417/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function.…
AnalizadaMedia (5.4)0.33%—Zephyr-one Zephyr Project Manager3/8/202417/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,…