Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.37%—Bajorat-media PB SEO Friendly Images4/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PB SEO Friendly Images plugin <= 4.0.5 versions.
ModificadaMedia (5.4)0.36%—Olevmedia Shortcodes3/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 versions.
ModificadaCrítica (9.8)2.3%💥 PoCMediawiki Score15/4/202317/6/2026
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted…
ModificadaMedia (4.3)0.83%—Mediawiki15/4/202317/6/2026
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This…
ModificadaMedia (4.8)0.47%—Auto Rename Media ON Upload Project Auto Rename Media ON Upload10/4/202317/6/2026
The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaCrítica (9.8)1.2%—MediawikiFedoraproject Fedora31/3/202317/6/2026
An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
ModificadaMedia (5.3)0.44%—Mediawiki31/3/202317/6/2026
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.
ModificadaMedia (6.5)0.58%—Mediawiki31/3/202317/6/2026
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUserLog API requests in some configurations, denial of service can occur (RequestTimeoutException or upstream request timeout).
ModificadaMedia (4.3)0.44%—Mediawiki31/3/202317/6/2026
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.
ModificadaMedia (4.8)0.39%—Jeffrey-wp Media Library Categories29/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeffrey-WP Media Library Categories plugin <= 1.9.9 versions.
ModificadaMedia (6.1)0.79%—Sprymedia Datatables6/3/202317/6/2026
Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a version from 2012.
ModificadaCrítica (9.8)4.4%💥 ExploitNajeebmedia Woocommerce Checkout Field Manager6/3/202317/6/2026
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
ModificadaMedia (6.1)0.59%—Media Downloader Project Media Downloader4/3/202317/6/2026
A vulnerability was found in Media Downloader Plugin 0.1.992 on WordPress. It has been declared as problematic. This vulnerability affects the function dl_file_resumable of the file getfile.php. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. Upgrading to…
ModificadaAlta (7.2)0.78%—Media Library Assistant Project Media Library Assistant27/2/202317/6/2026
The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
ModificadaMedia (5.4)0.49%—Olevmedia Shortcodes27/2/202317/6/2026
The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.46%—Devowl Real Media Library21/2/202317/6/2026
The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.23%—Intel Media Software Development KIT16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.20%—Intel Media Software Development KIT16/2/202317/6/2026
NULL pointer dereference in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Improper buffer restrictions in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Out-of-bounds read in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Media Software Development KIT16/2/202317/6/2026
Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)0.78%—Media-server Project Media-server15/2/202317/6/2026
Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service.
ModificadaMedia (6.1)0.38%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
ModificadaAlta (7.5)0.41%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. Insufficiently protected credential change.
ModificadaAlta (8.8)0.28%—Mediacp Media Control Panel15/2/202317/6/2026
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
Orbitaley — Vulnerabilidades