Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3694 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.23% | — | Digitalzoomstudio Zoomsounds | 5/4/2025 | 17/6/2026 | The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions… | |
| Analizada | Alta (8.1) | 0.35% | — | Digitalzoomstudio Zoomsounds | 5/4/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for… | |
| Aplazada | Media (6.8) | 0.26% | — | GitoxideAISha1 SmolAISha1AI | 4/4/2025 | 17/6/2026 | gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision… | |
| Aplazada | Media (6.5) | 0.24% | — | Hutsixdigital TigerAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0. | |
| Aplazada | Alta (7.4) | 0.58% | — | Jupyterlab-gitAI | 3/4/2025 | 17/6/2026 | jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Git repository under a name that includes a shell command substitution string in the syntax $(<command>). These directory names are allowed in macOS and a majority of Linux distributions. If a user… | |
| Aplazada | Alta (7.1) | 0.31% | — | Madfishdigital Bulk Noindex Nofollow ToolkitAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit bulk-noindex-nofollow-toolkit-by-mad-fish allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through <= 2.16. | |
| Aplazada | Media (6.5) | 0.36% | — | Digitalcourt Marketer AddonsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marketer Addons marketer-addons allows Stored XSS.This issue affects Marketer Addons: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.9) | 20% | — | Digital China Dcme-520AI | 31/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injection. The attack… | |
| Analizada | Media (6.5) | 0.27% | — | Gitlab | 28/3/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects. | |
| Analizada | Media (5.5) | 0.26% | — | Gitlab | 28/3/2025 | 17/6/2026 | An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request. | |
| Analizada | Media (6.5) | 0.21% | — | Gitlab | 27/3/2025 | 17/6/2026 | An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A specifically crafted issue could manipulate AI-assisted development features to potentially expose sensitive project data to unauthorized users. | |
| Analizada | Media (5.4) | 0.29% | — | Gitlab | 27/3/2025 | 17/6/2026 | An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec. | |
| Analizada | Alta (8.8) | 0.36% | — | Gitlab | 27/3/2025 | 17/6/2026 | An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects. | |
| Analizada | Media (5.4) | 0.29% | — | Gitlab | 27/3/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting. | |
| Analizada | Alta (8) | 0.25% | — | Gitlab | 27/3/2025 | 17/6/2026 | An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI… | |
| Aplazada | Media (6.1) | 0.33% | — | Digital License ManagerAI | 25/3/2025 | 17/6/2026 | The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (5.3) | 0.39% | — | Awesomemotive Easy Digital Downloads | 25/3/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post… | |
| Analizada | Media (5.1) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 20/3/2025 | 17/6/2026 | The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 allows an unauthorized user to obtain entry data from forms. | |
| Aplazada | Media (5.9) | 0.29% | — | HCL Digital ExperienceAIHCL Ring APIAIHCL DxclientAI | 20/3/2025 | 17/6/2026 | HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties. | |
| Aplazada | Crítica (9.8) | 4.9% | 💥 Exploit | Asylumdigital AGE GateAI | 20/3/2025 | 17/6/2026 | The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be… | |
| Analizada | Media (5.1) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 19/3/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's… | |
| Aplazada | Crítica (9.1) | 0.91% | 💥 PoC | Dorset DG 201 Digital LockAI | 17/3/2025 | 17/6/2026 | An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication. | |
| Analizada | Alta (7.5) | 0.46% | — | Gitlab | 13/3/2025 | 17/6/2026 | An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs. | |
| Analizada | Media (6.5) | 0.42% | — | Gitlab | 13/3/2025 | 17/6/2026 | An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only. | |
| Analizada | Alta (7.4) | 0.24% | — | Gitlab | 13/3/2025 | 17/6/2026 | An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code. |