Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.25% | — | Codexin Media Library Helper | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Media Library Helper plugin <= 1.2.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Social Media Icons Widget Project Social Media Icons Widget | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in akhlesh-nagar, a.Ankit Social Media Icons Widget plugin <= 1.6 versions. | |
| Modificada | Media (6.1) | 0.49% | — | Mediaburst Gravity Forms | 17/7/2023 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Media (5.5) | 0.35% | — | Adobe Media Encoder | 12/7/2023 | 17/6/2026 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Media (5.5) | 0.35% | — | Adobe Media Encoder | 12/7/2023 | 17/6/2026 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Media (5.5) | 0.35% | — | Adobe Media Encoder | 12/7/2023 | 17/6/2026 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Alta (7.8) | 0.36% | — | Adobe Media Encoder | 12/7/2023 | 17/6/2026 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Media (4.3) | 0.39% | — | Graphpaperpress Sell Media | 12/7/2023 | 17/6/2026 | The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the sell_media_process() function. This makes it possible for unauthenticated attackers to sell media paypal orders via a forged request… | |
| Modificada | Alta (7.5) | 0.99% | — | Linuxfoundation YoctoMediatek Mt7603 FirmwareMediatek Mt7613 FirmwareMediatek Mt7615 Firmware+8 | 4/7/2023 | 17/6/2026 | In Wi-Fi, there is a possible low throughput due to misrepresentation of critical information. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220829014; Issue ID: GN20220829014. | |
| Modificada | Media (5.3) | 0.61% | — | Mediawiki | 30/6/2023 | 17/6/2026 | An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces. | |
| Modificada | Media (5.4) | 0.50% | — | Mediawiki | 30/6/2023 | 17/6/2026 | An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature. | |
| Modificada | Crítica (9.8) | 0.95% | — | Mediawiki | 30/6/2023 | 17/6/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message. | |
| Modificada | Media (6.1) | 0.69% | — | Mediawiki | 30/6/2023 | 17/6/2026 | An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute). | |
| Modificada | Media (5.3) | 0.34% | — | Mediawiki | 30/6/2023 | 17/6/2026 | An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur. | |
| Modificada | Media (5.3) | 0.67% | — | Mediawiki | 30/6/2023 | 17/6/2026 | An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users. | |
| Modificada | Media (6.1) | 0.47% | — | Mediawiki | 29/6/2023 | 17/6/2026 | An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs. | |
| Modificada | Media (6.1) | 0.47% | — | Mediawiki | 29/6/2023 | 17/6/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header. | |
| Modificada | Media (6.1) | 0.47% | — | Mediawiki | 29/6/2023 | 17/6/2026 | An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format. | |
| Modificada | Media (6.1) | 0.40% | — | Mediawiki | 29/6/2023 | 17/6/2026 | An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs. | |
| Modificada | Media (6.1) | 0.83% | — | Mediawiki | 26/6/2023 | 17/6/2026 | Se descubrió un problema en MediaWiki antes de 1.35.11, 1.36.x hasta 1.38.x antes de 1.38.7 y 1.39.x antes de 1.39.4. BlockLogFormatter.php en BlockLogFormatter permite XSS en la función de bloques parciales. | |
| Modificada | Alta (8.1) | 0.60% | — | Easy Media Replace Project Easy Media Replace | 19/6/2023 | 17/6/2026 | Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions. | |
| Modificada | Media (6.8) | 0.51% | — | VW Discover Media Infotainment System | 16/6/2023 | 17/6/2026 | A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers to cause a Denial of Service (DoS) via supplying crafted media files when connecting a device to the vehicle's USB plug and play feature. | |
| Modificada | Media (5.3) | 0.80% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This… | |
| Modificada | Alta (8.8) | 1.9% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin… |