Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.45%—Infoway Ebook Downloader12/2/202517/6/2026
The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers…
ModificadaMedia (6.1)0.45%—Shopfiles Ebook Store21/12/202417/6/2026
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (6.1)0.36%—Shopfiles Ebook Store21/12/202417/6/2026
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.8001. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they…
ModificadaCrítica (9.8)1.0%—Shopfiles Ebook Store9/12/202417/6/2026
Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.
AplazadaMedia (6.5)0.25%—Ezyonlinebookings Online Booking System WidgetAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EzyOnlineBookings EzyOnlineBookings Online Booking System Widget ezyonlinebookings-online-booking-system allows DOM-Based XSS.This issue affects EzyOnlineBookings Online Booking System Widget: from n/a through <= 1.3.
AplazadaAlta (7.4)0.35%—Facebook Chat PluginAI16/10/202417/6/2026
The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site…
AplazadaMedia (5.3)0.35%—Facebook ThriftAI27/9/202417/6/2026
A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.
AplazadaAlta (7.5)0.48%—Facebook ThriftAI27/9/202417/6/2026
A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.
AplazadaMedia (6.8)0.27%—Lenovo Thinkpad L390 YogaAILenovo 10W NotebookAI13/9/202417/6/2026
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
AplazadaMedia (6.7)0.17%—Lenovo NotebookAI13/9/202417/6/2026
A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.
AnalizadaMedia (6.1)0.44%—Wpsimplebookingcalendar WP Simple Booking Calendar13/9/202417/6/2026
The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.10. This makes it possible for unauthenticated attackers to inject arbitrary web…
AnalizadaMedia (4.3)0.23%—Themetechmount Truebooker8/9/202417/6/2026
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
AnalizadaCrítica (9.8)3.3%💥 ExploitThemetechmount Truebooker8/9/202417/6/2026
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
AnalizadaMedia (6.1)0.40%—JupyterlabJupyter Notebook28/8/202417/6/2026
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature. A malicious user can access any data…
AnalizadaAlta (7.1)14%—Calibre-ebook Calibre6/8/202417/6/2026
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
AnalizadaMedia (6.1)26%💥 ExploitCalibre-ebook Calibre6/8/202417/6/2026
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
AplazadaCrítica (9.8)84%💥 ExploitCalibre-ebook CalibreAI6/8/202417/6/2026
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
AnalizadaAlta (7.5)62%💥 ExploitCalibre-ebook Calibre6/8/202417/6/2026
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
ModificadaMedia (5.3)0.45%—Shopfiles Ebook Store2/8/202417/6/2026
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to…
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
AplazadaAlta (7.5)10%—Promokit Facebook ModuleAIPrestashopAI19/6/202417/6/2026
In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
AnalizadaMedia (6.8)0.18%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
AnalizadaMedia (6.8)0.17%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
ModificadaCrítica (9.1)0.54%—Dnkorpushov Ebookmeta7/6/202417/6/2026
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
ModificadaAlta (7.5)0.50%—Dnkorpushov Ebookmeta7/6/202417/6/2026
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
Orbitaley — Vulnerabilidades