Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | ClamavCisco Secure EndpointCisco Secure Endpoint Private Cloud | 22/1/2025 | 17/6/2026 | A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read.… | |
| Aplazada | Alta (7.5) | 0.54% | — | Deluxethemes Private Messages FOR UserproAI | 21/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DeluxeThemes Private Messages for UserPro userpro-messaging.This issue affects Private Messages for UserPro: from n/a through <= 4.10.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Silverplugins217 Build Private Store FOR WoocommerceAI | 15/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Cross Site Request Forgery.This issue affects Build Private Store For Woocommerce: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.25% | — | Bigid PrivacyportalAI | 13/1/2025 | 17/6/2026 | BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function. | |
| Analizada | Media (5.5) | 0.19% | — | Private Content Project Private Content | 9/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue affects Private content: from 0.0.0 before 2.1.0. | |
| Aplazada | Alta (8.8) | 0.41% | — | Amentotech Private Limited WpguppyAIAmentotech Private Limited Wpguppy LiteAI | 7/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalation.This issue affects WPGuppy: from n/a through <= 1.1.0. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Amenotech Private Limited WpguppyAI | 7/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0. | |
| Aplazada | Media (5.3) | 0.45% | — | Wpexpertdeveloper WP Private Content PlusAI | 6/12/2024 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles… | |
| Analizada | Crítica (9.8) | 2.7% | — | Pribai Privategpt | 14/11/2024 | 17/6/2026 | A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/privategpt application, versions up to and including 0.3.0. The vulnerability arises due to the use of the `eval()` function to parse a string… | |
| Modificada | Media (6.1) | 0.31% | — | Marianheddesheimer Extra Privacy FOR Elementor | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marian Heddesheimer Extra Privacy for Elementor extra-privacy-for-elementor allows Reflected XSS.This issue affects Extra Privacy for Elementor: from n/a through <= 0.1.3. | |
| Aplazada | Media (6.1) | 0.38% | — | Embed Videos AND Respect PrivacyAI | 11/10/2024 | 17/6/2026 | The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.5) | 0.31% | — | Mediajedi User Private Files | 22/8/2024 | 17/6/2026 | The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.63% | — | PrivatebinAIYourlsAI | 9/7/2024 | 17/6/2026 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance without authentication and/or exposing the authentication token to the public,… | |
| Analizada | Media (6.1) | 30% | 💥 Exploit | Pribai Privategpt | 27/6/2024 | 17/6/2026 | An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerability includes potential… | |
| Analizada | Media (5.4) | 0.18% | — | Pribai Privategpt | 27/6/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users. | |
| Analizada | Alta (7.2) | 0.34% | — | Pribai Privategpt | 6/6/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that could result in unauthorized access to the local network and potentially sensitive information. Specifically, by manipulating the… | |
| Aplazada | Media (5.1) | 1.9% | — | Huashi Private Cloud CDN Live Streaming Acceleration ServerAI | 23/5/2024 | 17/6/2026 | A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack… | |
| Analizada | Media (5.4) | 0.32% | — | Pribai Privategpt | 16/5/2024 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's… | |
| Analizada | Alta (7.5) | 1.1% | — | Pribai Privategpt | 16/5/2024 | 17/6/2026 | imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI to retrieve or… | |
| Aplazada | Media (5.3) | 0.45% | — | Subway Private Site OptionAI | 2/5/2024 | 17/6/2026 | The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's private site feature and view restricted page and post content. | |
| Analizada | Media (5.9) | 5.5% | — | Microsoft Azure Private 5G Core | 9/4/2024 | 17/6/2026 | Azure Private 5G Core Denial of Service Vulnerability | |
| Aplazada | Crítica (9.8) | 1.1% | — | Huashi Private Cloud CDN Live Streaming Acceleration Server Hgateway-sixportAI | 29/3/2024 | 17/6/2026 | An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component. | |
| Aplazada | Alta (7.9) | 0.19% | — | Sandisk PrivateaccessAI | 13/3/2024 | 17/6/2026 | A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system user. This vulnerability is only exploitable locally if an attacker has access to a copy of the user's vault or has already gained access into a user's… | |
| Modificada | Media (5.3) | 0.47% | — | Shellcreeper F(x) Private Site | 12/3/2024 | 17/6/2026 | The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin. | |
| Modificada | Media (5.3) | 0.46% | — | Zatzlabs MY Private Site | 29/2/2024 | 17/6/2026 | The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's site privacy feature and view restricted page and post content. |