Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Bajorat-media PB SEO Friendly Images | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PB SEO Friendly Images plugin <= 4.0.5 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Olevmedia Shortcodes | 3/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 versions. | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Mediawiki Score | 15/4/2023 | 17/6/2026 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted… | |
| Modificada | Media (4.3) | 0.83% | — | Mediawiki | 15/4/2023 | 17/6/2026 | An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This… | |
| Modificada | Media (4.8) | 0.47% | — | Auto Rename Media ON Upload Project Auto Rename Media ON Upload | 10/4/2023 | 17/6/2026 | The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 1.2% | — | MediawikiFedoraproject Fedora | 31/3/2023 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header. | |
| Modificada | Media (5.3) | 0.44% | — | Mediawiki | 31/3/2023 | 17/6/2026 | An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted. | |
| Modificada | Media (6.5) | 0.58% | — | Mediawiki | 31/3/2023 | 17/6/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. When a user with checkuserlog permissions makes many CheckUserLog API requests in some configurations, denial of service can occur (RequestTimeoutException or upstream request timeout). | |
| Modificada | Media (4.3) | 0.44% | — | Mediawiki | 31/3/2023 | 17/6/2026 | An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users. | |
| Modificada | Media (4.8) | 0.39% | — | Jeffrey-wp Media Library Categories | 29/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeffrey-WP Media Library Categories plugin <= 1.9.9 versions. | |
| Modificada | Media (6.1) | 0.79% | — | Sprymedia Datatables | 6/3/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a version from 2012. | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Najeebmedia Woocommerce Checkout Field Manager | 6/3/2023 | 17/6/2026 | The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server | |
| Modificada | Media (6.1) | 0.59% | — | Media Downloader Project Media Downloader | 4/3/2023 | 17/6/2026 | A vulnerability was found in Media Downloader Plugin 0.1.992 on WordPress. It has been declared as problematic. This vulnerability affects the function dl_file_resumable of the file getfile.php. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. Upgrading to… | |
| Modificada | Alta (7.2) | 0.78% | — | Media Library Assistant Project Media Library Assistant | 27/2/2023 | 17/6/2026 | The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Media (5.4) | 0.49% | — | Olevmedia Shortcodes | 27/2/2023 | 17/6/2026 | The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.46% | — | Devowl Real Media Library | 21/2/2023 | 17/6/2026 | The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.5) | 0.23% | — | Intel Media Software Development KIT | 16/2/2023 | 17/6/2026 | Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.20% | — | Intel Media Software Development KIT | 16/2/2023 | 17/6/2026 | NULL pointer dereference in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Media Software Development KIT | 16/2/2023 | 17/6/2026 | Improper buffer restrictions in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Media Software Development KIT | 16/2/2023 | 17/6/2026 | Out-of-bounds read in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Media Software Development KIT | 16/2/2023 | 17/6/2026 | Protection mechanism failure in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.78% | — | Media-server Project Media-server | 15/2/2023 | 17/6/2026 | Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service. | |
| Modificada | Media (6.1) | 0.38% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint. | |
| Modificada | Alta (7.5) | 0.41% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. Insufficiently protected credential change. | |
| Modificada | Alta (8.8) | 0.28% | — | Mediacp Media Control Panel | 15/2/2023 | 17/6/2026 | Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint. |