Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

2779 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Social Media AND Share IconsAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
AplazadaCrítica (9.8)0.50%—WP Social Media LoginAI22/8/202626/8/2026
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.
AplazadaMedia (6.8)0.39%—Media Library AssistantAI21/8/202626/8/2026
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
AplazadaMedia (6.5)0.22%—Media Library AssistantAI20/8/202620/8/2026
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
AplazadaCrítica (9.1)0.50%—Media Library AssistantAI20/8/202620/8/2026
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
AplazadaCrítica (9.3)0.40%—Rtcamp RtmediaAI20/8/202620/8/2026
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
AplazadaCrítica (9.3)0.40%—Calmar-webmedia Total DonationsAI19/8/202620/8/2026
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
AplazadaCrítica (9.8)0.48%—Calmar-webmedia Total DonationsAI19/8/202620/8/2026
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
AplazadaMedia (6.8)0.43%💥 PoCEasy Media ReplaceAI19/8/202626/8/2026
The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who…
AplazadaMedia (6.5)0.22%—Davidlingren Media Library AssistantAI18/8/202621/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
AplazadaAlta (8.6)0.58%—Mediawiki MapsAI18/8/20269/9/2026
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a…
AplazadaAlta (7.2)0.42%—Platnosci Online Blue MediaAI16/8/202620/8/2026
The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by…
AplazadaMedia (6.4)0.41%—Fastlinemedia Beaver BuilderAI15/8/202620/8/2026
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.8)0.34%—Wso2 Class MediatorAI6/8/202631/8/2026
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive…
AplazadaAlta (7.1)0.25%—Media Library AssistantAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
AplazadaCrítica (9.8)2.9%💥 PoCOpenmediavault-mdAI3/8/20269/9/2026
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.
AnalizadaMedia (6)0.17%—Mediatek Mt6991 FirmwareMediatek Mt8768 FirmwareMediatek Mt8791t FirmwareMediatek Mt8792 Firmware+63/8/202619/8/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
AnalizadaMedia (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+73/8/202619/8/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
AnalizadaMedia (4.4)0.15%—Mediatek Mt6983 FirmwareMediatek Mt8676 FirmwareMediatek Mt8678 FirmwareMediatek Mt8755 Firmware+133/8/202619/8/2026
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
AnalizadaAlta (7.8)0.15%—Mediatek Mt7925 FirmwareMediatek Mt7927 FirmwareMediatek Mt7902 FirmwareMediatek Mt7920 Firmware+23/8/202619/8/2026
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
AnalizadaMedia (5.5)0.15%—Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware3/8/202619/8/2026
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID:…
AnalizadaMedia (4.4)0.14%—Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware3/8/202619/8/2026
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.
AnalizadaMedia (5.5)0.11%—Mediatek Mt6990 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 Firmware+23/8/202619/8/2026
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735,…
AnalizadaMedia (5.5)0.15%—Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 FirmwareMediatek Mt6988 Firmware+13/8/202619/8/2026
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue…
AnalizadaMedia (4.4)0.14%—Mediatek Mt6813 FirmwareMediatek Mt6982vb FirmwareMediatek Mt6986 FirmwareMediatek Mt6986d Firmware+13/8/202619/8/2026
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.