Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (6.4) | 0.36% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the… | |
| Aplazada | Media (6.4) | 0.36% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the… | |
| Aplazada | Media (6.4) | 0.42% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI | 9/9/2026 | 10/9/2026 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Live555 Streaming MediaAI | 9/9/2026 | 14/9/2026 | A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server. | |
| Aplazada | Media (5.3) | 0.24% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 14/9/2026 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build… | |
| Aplazada | Alta (7.3) | 0.12% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 18/9/2026 | VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process. | |
| Analizada | Alta (8.8) | 0.48% | — | Microsoft WEB Media Extensions | 8/9/2026 | 30/9/2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (7.1) | 0.35% | — | Avideo SocialmediapublisherAIWwbn AvideoAI | 8/9/2026 | 8/9/2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored… | |
| Aplazada | Media (6.5) | 0.27% | — | Fastlinemedia Beaver BuilderAI | 8/9/2026 | 8/9/2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Analizada | Media (5.3) | 0.19% | — | Mediatek Mt2735 FirmwareMediatek Mt6833 FirmwareMediatek Mt6853 FirmwareMediatek Mt6855 Firmware+15 | 7/9/2026 | 9/9/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue… | |
| Analizada | Media (5.3) | 0.19% | — | Mediatek Mt2716 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6813 Firmware+53 | 7/9/2026 | 9/9/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue… | |
| Analizada | Alta (8.4) | 0.13% | — | Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+49 | 7/9/2026 | 9/9/2026 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | |
| Analizada | Alta (8.4) | 0.13% | — | Mediatek Mt2718 FirmwareMediatek Mt6580 FirmwareMediatek Mt6739 FirmwareMediatek Mt6761 Firmware+49 | 7/9/2026 | 9/9/2026 | In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | |
| Analizada | Media (5.5) | 0.09% | — | Mediatek Mt2716 FirmwareMediatek Mt6835 FirmwareMediatek Mt6858 FirmwareMediatek Mt6878 Firmware+18 | 7/9/2026 | 9/9/2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232. | |
| Aplazada | Media (6.1) | 0.17% | — | Fastlinemedia Beaver BuilderAI | 5/9/2026 | 8/9/2026 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… | |
| Aplazada | Crítica (9.3) | 3.4% | — | Zbtlink We1326AIZbtlink We357AIZbtlink We5926AIZbtlink We5926 WDAI+12 | 27/8/2026 | 24/9/2026 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | CP Media PlayerAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | |
| Aplazada | Media (6.9) | 0.52% | — | ZlmediakitAI | 26/8/2026 | 23/9/2026 | ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the relative-path argument is empty that helper… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Drupal Media FoldersAI | 25/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | |
| Aplazada | Media (5.6) | 0.19% | — | MediasoupAI | 25/8/2026 | 9/9/2026 | mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC,… | |
| Aplazada | Media (4.9) | 0.51% | — | Media SweepAI | 25/8/2026 | 28/9/2026 | The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… |