Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Social Media AND Share IconsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |
| Aplazada | Crítica (9.8) | 0.50% | — | WP Social Media LoginAI | 22/8/2026 | 26/8/2026 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address. | |
| Aplazada | Media (6.8) | 0.39% | — | Media Library AssistantAI | 21/8/2026 | 26/8/2026 | The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. | |
| Aplazada | Media (6.5) | 0.22% | — | Media Library AssistantAI | 20/8/2026 | 20/8/2026 | Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Media Library AssistantAI | 20/8/2026 | 20/8/2026 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Rtcamp RtmediaAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |
| Aplazada | Media (6.8) | 0.43% | 💥 PoC | Easy Media ReplaceAI | 19/8/2026 | 26/8/2026 | The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who… | |
| Aplazada | Media (6.5) | 0.22% | — | Davidlingren Media Library AssistantAI | 18/8/2026 | 21/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39. | |
| Aplazada | Alta (8.6) | 0.58% | — | Mediawiki MapsAI | 18/8/2026 | 9/9/2026 | Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a… | |
| Aplazada | Alta (7.2) | 0.42% | — | Platnosci Online Blue MediaAI | 16/8/2026 | 20/8/2026 | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by… | |
| Aplazada | Media (6.4) | 0.41% | — | Fastlinemedia Beaver BuilderAI | 15/8/2026 | 20/8/2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.8) | 0.34% | — | Wso2 Class MediatorAI | 6/8/2026 | 31/8/2026 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive… | |
| Aplazada | Alta (7.1) | 0.25% | — | Media Library AssistantAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | |
| Aplazada | Crítica (9.8) | 2.9% | 💥 PoC | Openmediavault-mdAI | 3/8/2026 | 9/9/2026 | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters. | |
| Analizada | Media (6) | 0.17% | — | Mediatek Mt6991 FirmwareMediatek Mt8768 FirmwareMediatek Mt8791t FirmwareMediatek Mt8792 Firmware+6 | 3/8/2026 | 19/8/2026 | In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765. | |
| Analizada | Media (6) | 0.17% | — | Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+7 | 3/8/2026 | 19/8/2026 | In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941. | |
| Analizada | Media (4.4) | 0.15% | — | Mediatek Mt6983 FirmwareMediatek Mt8676 FirmwareMediatek Mt8678 FirmwareMediatek Mt8755 Firmware+13 | 3/8/2026 | 19/8/2026 | In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132. | |
| Analizada | Alta (7.8) | 0.15% | — | Mediatek Mt7925 FirmwareMediatek Mt7927 FirmwareMediatek Mt7902 FirmwareMediatek Mt7920 Firmware+2 | 3/8/2026 | 19/8/2026 | In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296. | |
| Analizada | Media (5.5) | 0.15% | — | Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware | 3/8/2026 | 19/8/2026 | In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID:… | |
| Analizada | Media (4.4) | 0.14% | — | Mediatek Mt6890 FirmwareMediatek Mt6988 FirmwareMediatek Mt6990 Firmware | 3/8/2026 | 19/8/2026 | In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575. | |
| Analizada | Media (5.5) | 0.11% | — | Mediatek Mt6990 FirmwareMediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6880 Firmware+2 | 3/8/2026 | 19/8/2026 | In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735,… | |
| Analizada | Media (5.5) | 0.15% | — | Mediatek Mt2735 FirmwareMediatek Mt2737 FirmwareMediatek Mt6890 FirmwareMediatek Mt6988 Firmware+1 | 3/8/2026 | 19/8/2026 | In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue… | |
| Analizada | Media (4.4) | 0.14% | — | Mediatek Mt6813 FirmwareMediatek Mt6982vb FirmwareMediatek Mt6986 FirmwareMediatek Mt6986d Firmware+1 | 3/8/2026 | 19/8/2026 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669. |