Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.41%—Uxthemes Flatsome23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UX-themes Flatsome plugin <= 3.16.8 versions.
ModificadaAlta (8.8)0.25%—Piwebsolution Advanced-free-flat-shipping-woocommerce11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions.
ModificadaCrítica (9.8)0.89%—Flatnest Project Flatnest30/6/202317/6/2026
All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file.
ModificadaMedia (4.3)0.88%—Flatpak16/3/202317/6/2026
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide those permissions from users of the `flatpak(1)` command-line interface by…
ModificadaMedia (6.5)0.87%—Flatpak16/3/202317/6/2026
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak app is run on a Linux virtual console…
ModificadaMedia (4.8)0.53%—Flatpress2/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaMedia (5.4)0.48%—Flatpress2/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaMedia (5.4)0.48%—Flatpress2/3/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaMedia (5.4)0.52%—Flatpress2/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaMedia (6.1)0.58%—Flatpress2/3/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaAlta (8.1)0.71%—Flatpress1/3/202317/6/2026
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaMedia (5.4)0.60%—Flatpress1/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaCrítica (9.8)3.6%—Flatpress22/2/202317/6/2026
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaAlta (7.8)0.31%—Flatcc Project Flatcc17/2/202317/6/2026
Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the error_ref_sym function.
ModificadaMedia (5.4)0.44%—Flatcore16/2/202317/6/2026
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.
ModificadaMedia (6.1)0.51%—Flatpress28/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown processing of the file setup/lib/main.lib.php of the component Setup. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is…
ModificadaMedia (6.1)0.51%—Flatpress28/12/202217/6/2026
A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the file admin/panels/uploader/admin.uploader.php of the component XML File Handler/MD File Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of…
ModificadaMedia (6.1)0.52%—Flatpress28/12/202217/6/2026
A vulnerability classified as problematic has been found in FlatPress. This affects an unknown part of the file admin/panels/entry/admin.entry.list.php of the component Admin Area. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is…
ModificadaMedia (6.1)0.52%—Flatpress27/12/202217/6/2026
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument mm-newgallery-name leads to cross site scripting. The attack may be…
ModificadaCrítica (9.8)0.87%—Flatpress27/12/202217/6/2026
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is…
ModificadaCrítica (9.8)1.2%—Flat Project Flat25/12/202217/6/2026
A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to initiate the attack remotely.…
ModificadaMedia (5.4)0.55%—Flatpress18/12/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaCrítica (9.8)35%—Flatpress18/12/202217/6/2026
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
ModificadaMedia (5.4)0.88%—Mehanoid Flat PM12/12/202217/6/2026
The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.43%—Flatcore-cms9/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.