Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.21% | — | Opentext WEB Site Management Server | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that… | |
| Analizada | Media (5.9) | 0.16% | — | Opentext WEB Site Management Server | 19/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously. This issue affects Web… | |
| Aplazada | Media (5.3) | 0.29% | — | Alttextai Alttext AIAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.10.15. | |
| Aplazada | Crítica (9.5) | 0.35% | — | Opentext Directory ServicesAI | 18/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3… | |
| Aplazada | Media (5.3) | 0.36% | — | Context BlogAI | 18/2/2026 | 17/6/2026 | The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected,… | |
| Aplazada | Media (6.7) | 0.25% | — | Textcrawler PROAI | 11/2/2026 | 17/6/2026 | TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash. | |
| Aplazada | Baja (2.7) | 0.39% | — | Wikimedia TextextractsAI | 3/2/2026 | 17/6/2026 | Vulnerability in Wikimedia Foundation TextExtracts. This vulnerability is associated with program files includes/ApiQueryExtracts.Php. This issue affects TextExtracts: from * before 1.39.14, 1.43.4, 1.44.1. | |
| Aplazada | Alta (7.5) | 30% | — | Huggingface Text-generation-inferenceAI | 2/2/2026 | 17/6/2026 | A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET request, reading the… | |
| Aplazada | Media (6.9) | 0.10% | — | Opentext VerticaAI | 30/1/2026 | 17/6/2026 | Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data. The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X. | |
| Aplazada | Alta (8.7) | 0.70% | — | TextpatternAI | 23/1/2026 | 17/6/2026 | Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.9. | |
| Aplazada | Media (4.3) | 0.24% | — | TextmetricsAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Israpil Textmetrics webtexttool allows Code Injection.This issue affects Textmetrics: from n/a through <= 3.6.5. | |
| Analizada | Alta (8.6) | 0.62% | — | Jaraco.context | 20/1/2026 | 17/6/2026 | jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the… | |
| Aplazada | Media (5.3) | 0.46% | — | Swift W3C TracecontextAISwift OtelAI | 19/1/2026 | 17/6/2026 | Swift W3C TraceContext is a Swift implementation of the W3C Trace Context standard, and Swift OTel is an OpenTelemetry Protocol (OTLP) backend for Swift Log, Swift Metrics, and Swift Distributed Tracing. Prior to Swift W3C TraceContext version 1.0.0-beta.5 and Swift OTel version 1.0.4, a denial-of-service… | |
| Modificada | Media (5.3) | 0.83% | — | Phphtmledit Rich Text Editor | 13/1/2026 | 17/6/2026 | CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal… | |
| Aplazada | Media (6.4) | 0.25% | — | Curved TextAI | 9/1/2026 | 17/6/2026 | The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arctext shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (4.3) | 0.20% | — | Wptexture Image Slider SlideshowAI | 8/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through <= 1.8. | |
| Aplazada | Media (6.5) | 0.16% | — | Codeaffairs WP Text Slider WidgetAI | 29/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Text Slider Widget wp-text-slider-widget allows Stored XSS.This issue affects Wp Text Slider Widget: from n/a through <= 1.0. | |
| Analizada | Media (6.3) | 7.2% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 17/6/2026 | In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git refs, enabling… | |
| Modificada | Media (5.1) | 0.31% | — | Textpattern | 17/12/2025 | 17/6/2026 | Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users. | |
| Analizada | Media (6.4) | 7.0% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 30/9/2026 | In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other… | |
| Analizada | Media (6.5) | 8.1% | — | Lfprojects Model Context Protocol Servers | 17/12/2025 | 30/9/2026 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required… | |
| Analizada | Crítica (9.8) | 0.53% | 💥 PoC | Sublimetext Sublime Text 3 | 9/12/2025 | 17/6/2026 | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the Sublime Text application. | |
| Aplazada | Media (5.3) | 0.28% | — | Sevenspark Contact Form 7 Dynamic Text ExtensionAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.5. | |
| Aplazada | Media (4.3) | 0.13% | — | Valerio Monti Auto ALT TextAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Valerio Monti Auto Alt Text auto-alt-text allows Cross Site Request Forgery.This issue affects Auto Alt Text: from n/a through <= 2.5.2. |