Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.63% | — | WP Youtube Lyte Project WP Youtube Lyte | 12/7/2021 | 17/6/2026 | The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues. | |
| Modificada | Alta (8.8) | 1.0% | — | Meomundo Related Youtube Videos | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.5) | 0.52% | — | Embedplus Youtube | 17/11/2017 | 17/6/2026 | CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | MDC Youtube Downloader Project MDC Youtube Downloader | 23/5/2017 | 17/6/2026 | Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php. | |
| Modificada | Baja (3.5) | 1.3% | — | Youtube Embed Project Youtube Embed | 31/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter). | |
| Modificada | Alta (9.3) | 3.8% | — | Gogago Youtube Video Converter | 1/1/2015 | 16/6/2026 | Buffer overflow in the Download method in a certain ActiveX control in MDIEEx.dll in Gogago YouTube Video Converter 1.1.6 allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Joomlaboat COM Youtubegallery | 21/7/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php. | |
| Modificada | Media (4.3) | 1.9% | — | Joomlaboat COM Youtubegallery | 25/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) component 3.4.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the videofile parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Prasanna COM Youtube | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Videoscript Youtube Video Script | 28/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Greatclone Youtuber Clone | 31/7/2008 | 16/6/2026 | SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Carlos Desseno Youtube Blog | 25/7/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_archivo parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Carlos Desseno Youtube Blog | 25/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or HTML via the m parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Youtube Blog | 25/7/2008 | 16/6/2026 | SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Youtube Blog | 25/7/2008 | 16/6/2026 | SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3307. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Buyscripts Vshare Youtube Clone | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Youtube Clone Script | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter. | |
| Modificada | Alta (9.3) | 1.8% | — | Generic Youtube Clone Script | 15/7/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Hispah Youtube Clone Script | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter. |