Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
6912 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.23% | — | Cookies Consent Manager Project Cookies Coonsent Manager | 14/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14. | |
| Analizada | Alta (7.5) | 0.45% | — | Dbsyncer Project Dbsyncer | 5/5/2025 | 17/6/2026 | Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password. | |
| Modificada | Media (5.4) | 0.27% | — | Dbsyncer Project Dbsyncer | 5/5/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter. | |
| Analizada | Alta (7.3) | 0.39% | — | Ueditor Project Ueditor | 23/4/2025 | 1/10/2026 | Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*. | |
| Modificada | Media (6.1) | 0.31% | — | Zephyr-one Zephyr Project Manager | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through <= 3.3.101. | |
| Analizada | Media (5.9) | 0.32% | — | Google Maps\ Store Locator Project | 16/4/2025 | 17/6/2026 | Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*. | |
| Aplazada | Media (5.4) | 0.35% | — | Dylan James Zephyr Project ManagerAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.200. | |
| Aplazada | Media (6.9) | 0.23% | — | Ts-asn1-der Project Ts-asn1-derAI | 7/4/2025 | 17/6/2026 | ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding can lead to denial on service for absolute values in the range 2**31 -- 2**32 - 1. The arithmetic in the numBitLen didn't take into account that values in this range could result in a negative result… | |
| Analizada | Crítica (9.8) | 0.43% | — | Oauth2 Server Project Oauth2 Server | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. | |
| Analizada | Baja (3.5) | 0.26% | — | Simple Banner Project Simple Banner | 25/3/2025 | 17/6/2026 | The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (8.8) | 0.62% | — | Umeditor Project Umeditor | 3/3/2025 | 17/6/2026 | A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element. | |
| Analizada | Baja (3.8) | 0.34% | — | Crelly Slider Project Crelly Slider | 27/1/2025 | 17/6/2026 | The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.1) | 0.17% | — | MDC Youtube Downloader Project MDC Youtube Downloader | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows Stored XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0. | |
| Aplazada | Media (4) | 0.13% | — | Notaryproject Notation-goAI | 13/1/2025 | 17/6/2026 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revocation status of the certificate(s) used to generate the timestamp… | |
| Analizada | Baja (3.3) | 0.19% | — | Notaryproject Notation-go | 13/1/2025 | 17/6/2026 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature. After retrieving the CRL, notation-go attempts to update the… | |
| Analizada | Alta (8.8) | 0.20% | — | Migrate Queue Importer Project Migrate Queue Importer | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1. | |
| Analizada | Crítica (9.1) | 0.37% | — | Swift Mailer Project Swift Mailer | 9/1/2025 | 17/6/2026 | Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*. | |
| Aplazada | Alta (7.5) | 0.60% | — | Matter Project ChipAIConnectedhomeipAI | 18/12/2024 | 17/6/2026 | In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service. | |
| Modificada | Media (5.4) | 0.31% | — | MDC Youtube Downloader Project MDC Youtube Downloader | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows DOM-Based XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0. | |
| Analizada | Media (5.5) | 0.20% | — | Linux KernelFedoraproject Fedora | 14/11/2024 | 17/6/2026 | A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service. | |
| Analizada | Alta (7.1) | 0.32% | — | Dylanjkotze Zephyr Project Manager | 26/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102. | |
| Analizada | Media (5.4) | 0.26% | — | Zephyr-one Zephyr Project Manager | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102. | |
| Analizada | Crítica (9.8) | 0.37% | — | Zephyr-one Zephyr Project Manager | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100. | |
| Analizada | Alta (8.1) | 0.40% | — | Zephyr-one Zephyr Project Manager | 15/8/2024 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function.… | |
| Analizada | Media (5.4) | 0.33% | — | Zephyr-one Zephyr Project Manager | 3/8/2024 | 17/6/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,… |