Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

6915 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)3.2%💥 ExploitVideo List Manager Project Video List Manager8/5/202317/6/2026
The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaAlta (8.8)14%—Sloth Logo Customizer Project Sloth Logo Customizer8/5/202317/6/2026
The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
ModificadaMedia (6.5)0.33%—Enable/disable Auto Login When Register Project Enable/disable Auto Login When Register8/5/202317/6/2026
The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.1)0.51%—Cloud Manager Project Cloud Manager8/5/202317/6/2026
The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it in an admin panel, allowing unauthenticated attackers to trick a logged in admin to trigger a XSS payload by clicking a link.
ModificadaMedia (4.8)0.37%—Easy Event Calendar Project Easy Event Calendar8/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions.
ModificadaCrítica (9.8)1.4%—Djangoproject DjangoFedoraproject Fedora7/5/202317/6/2026
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading…
ModificadaMedia (6.5)0.93%—Struktur LibheifFedoraproject Fedora5/5/202317/6/2026
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
ModificadaMedia (4.8)0.37%—Sticky AD BAR Project Sticky AD BAR3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bon Plan Gratos Sticky Ad Bar plugin <= 1.3.1 versions.
ModificadaMedia (4.3)0.80%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.82%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.80%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
ModificadaMedia (4.3)0.97%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.65%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.86%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (4.3)0.80%—Google ChromeFedoraproject FedoraDebian Linux3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (8.8)0.76%—Google ChromeDebian LinuxFedoraproject Fedora3/5/202317/6/2026
Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
ModificadaAlta (7.1)0.69%—Google ChromeDebian LinuxFedoraproject Fedora3/5/202317/6/2026
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
ModificadaMedia (6.5)0.97%—Google ChromeDebian LinuxFedoraproject Fedora3/5/202317/6/2026
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)
ModificadaAlta (7.3)1.1%—MoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora2/5/202317/6/2026
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
ModificadaMedia (5.3)6.6%💥 ExploitMoodleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora2/5/202317/6/2026
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
ModificadaCrítica (9.8)1.1%—Antabot White-jotter Project Antabot White-jotter1/5/202317/6/2026
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload.
AnalizadaMedia (5.3)0.41%—Fedoraproject FedoraApple MacosNeovimVIM29/4/202324/9/2026
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
ModificadaMedia (5.5)0.26%—Canonical Cloud-initCanonical Ubuntu LinuxFedoraproject Fedora26/4/202317/6/2026
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
ModificadaAlta (7.8)6.1%💥 PoCGit-scm GITFedoraproject Fedora25/4/202317/6/2026
Git es un sistema de control de revisiones. Antes de las versiones 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3 y 2.40.1, una versión especialmente El archivo `.gitmodules` elaborado con URL de submódulo que tienen más de 1024 caracteres se puede usar para explotar un error en…
ModificadaBaja (2.2)0.96%—GIT FOR Windows Project GIT FOR WindowsFedoraproject Fedora25/4/202317/6/2026
En Git para Windows, la versión de Git para Windows, no se envían mensajes localizados con el instalador. Como consecuencia, se espera que Git no localice ningún mensaje y omita la inicialización de gettext. Sin embargo, debido a un cambio en los paquetes MINGW, la inicialización implícita de la función `gettext()` ya…
Orbitaley — Vulnerabilidades