Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.63%—WP Youtube Lyte Project WP Youtube Lyte12/7/202117/6/2026
The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.
ModificadaAlta (8.8)1.0%—Meomundo Related Youtube Videos5/7/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (6.5)0.52%—Embedplus Youtube17/11/201717/6/2026
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
ModificadaAlta (7.5)10%💥 ExploitMDC Youtube Downloader Project MDC Youtube Downloader23/5/201717/6/2026
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
ModificadaBaja (3.5)1.3%—Youtube Embed Project Youtube Embed31/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).
ModificadaAlta (9.3)3.8%—Gogago Youtube Video Converter1/1/201516/6/2026
Buffer overflow in the Download method in a certain ActiveX control in MDIEEx.dll in Gogago YouTube Video Converter 1.1.6 allows remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (7.5)2.3%💥 ExploitJoomlaboat COM Youtubegallery21/7/201417/6/2026
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.
ModificadaMedia (4.3)1.9%—Joomlaboat COM Youtubegallery25/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) component 3.4.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the videofile parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPrasanna COM Youtube30/7/201016/6/2026
SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.
ModificadaAlta (7.5)0.99%💥 ExploitVideoscript Youtube Video Script28/5/200916/6/2026
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)1.0%💥 ExploitGreatclone Youtuber Clone31/7/200816/6/2026
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.
ModificadaMedia (6.8)2.0%💥 ExploitCarlos Desseno Youtube Blog25/7/200816/6/2026
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_archivo parameter.
ModificadaMedia (4.3)3.6%💥 ExploitCarlos Desseno Youtube Blog25/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
ModificadaAlta (7.5)1.0%💥 ExploitYoutube Blog25/7/200816/6/2026
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.
ModificadaAlta (7.5)0.91%💥 ExploitYoutube Blog25/7/200816/6/2026
SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3307. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.1%💥 ExploitBuyscripts Vshare Youtube Clone14/5/200816/6/2026
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
ModificadaAlta (7.5)1.4%—Youtube Clone Script12/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter.
ModificadaAlta (9.3)1.8%—Generic Youtube Clone Script15/7/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.
ModificadaAlta (7.5)1.2%💥 ExploitHispah Youtube Clone Script3/7/200716/6/2026
SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.
Orbitaley — Vulnerabilidades