Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.3%💥 ExploitFlatpress11/10/20229/7/2026
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
ModificadaAlta (7.2)1.7%—Flatpress29/9/20229/7/2026
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
ModificadaMedia (5.4)1.8%💥 ExploitFlatpress23/6/202217/6/2026
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
ModificadaAlta (8.8)1.4%—Flatcore-cms16/6/202217/6/2026
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
ModificadaCrítica (9.8)19%—Flatcore-cms15/6/202217/6/2026
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
ModificadaMedia (5.4)0.48%—Flatcore-cms13/6/202217/6/2026
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
ModificadaMedia (6.1)0.71%—Flatcore-cms6/6/202217/6/2026
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.
ModificadaAlta (7.5)1.1%—Batflat1/3/202217/6/2026
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
ModificadaMedia (5.4)0.71%—Flatpress15/2/202217/6/2026
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.
ModificadaMedia (6.5)1.7%—FlatpakFlatpak-builderFedoraproject FedoraRedhat Enterprise Linux+113/1/202217/6/2026
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that is specified in the manifest, so running…
ModificadaAlta (8.6)1.3%—FlatpakFedoraproject FedoraRedhat Enterprise LinuxDebian Linux12/1/202217/6/2026
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the case that there's a null byte in the…
ModificadaMedia (6.1)0.76%—Duogeek Duofaq-responsive-flat-simple-faq14/12/202117/6/2026
The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.8.
ModificadaMedia (4.8)0.64%—Flat Preloader Project Flat Preloader1/11/202117/6/2026
The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaMedia (5.4)0.51%—Flat Preloader Project Flat Preloader1/11/202117/6/2026
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the…
ModificadaMedia (6.6)1.1%—Flatcore-cms28/10/202117/6/2026
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
ModificadaAlta (7.8)0.44%—FlatpakDebian LinuxFedoraproject Fedora8/10/202117/6/2026
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the…
ModificadaMedia (5.4)1.7%—Flatcore-cms23/8/202117/6/2026
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
ModificadaAlta (7.2)46%💥 ExploitFlatcore-cms23/8/202117/6/2026
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
ModificadaCrítica (9.1)0.99%—Netless Flat Server13/8/202117/6/2026
The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30 mishandles file ownership.
ModificadaCrítica (9.8)1.2%—Libp2p-deflate8/8/202117/6/2026
An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function.
ModificadaAlta (8.8)0.76%—Flatpress30/7/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
ModificadaCrítica (9.8)3.3%—Safe-flat Project Safe-flat26/4/202117/6/2026
Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaMedia (5.4)0.62%—Batflat11/3/202117/6/2026
Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
ModificadaMedia (5.4)0.62%—Batflat11/3/202117/6/2026
Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
ModificadaMedia (5.4)0.62%—Batflat11/3/202117/6/2026
Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name.
Orbitaley — Vulnerabilidades