Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Brandexponents Oshine ModulesAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Oshine Modules oshine-modules allows Reflected XSS.This issue affects Oshine Modules: from n/a through < 3.3.8. | |
| Analizada | Media (5.5) | 0.31% | — | Adobe Photoshop Elements | 11/2/2025 | 17/6/2026 | Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Aplazada | Media (5.4) | 0.26% | — | Brandexponents Oshine ModulesAI | 31/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Ihor KIT Shipping FOR Nova PoshtaAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping for Nova Poshta nova-poshta-ttn allows SQL Injection.This issue affects Shipping for Nova Poshta: from n/a through <= 1.19.6. | |
| Aplazada | Media (5.7) | 0.47% | — | InnoshopAI | 24/1/2025 | 17/6/2026 | InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload. | |
| Aplazada | Alta (7.5) | 0.46% | — | Niket Joshi Wpdb TO SQLAI | 22/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Niket Joshi WPDB to Sql wpdb-to-sql allows Retrieve Embedded Sensitive Data.This issue affects WPDB to Sql: from n/a through <= 1.2. | |
| Analizada | Alta (7.8) | 0.29% | — | Adobe Photoshop | 14/1/2025 | 17/6/2026 | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the… | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Photoshop | 14/1/2025 | 17/6/2026 | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (5.3) | 0.35% | — | Saoshyant Page BuilderAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in saoshyant1994 Saoshyant Page Builder saoshyant-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Saoshyant Page Builder: from n/a through <= 3.8. | |
| Aplazada | Media (6.1) | 0.45% | — | WOO UkrposhtaAI | 7/1/2025 | 17/6/2026 | The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and including, 1.17.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (6.3) | 0.77% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The… | |
| Analizada | Media (5.3) | 0.62% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to… | |
| Analizada | Media (6.9) | 0.57% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (10) | 0.57% | — | Huang Yaoshi Pharmaceutical Management SoftwareAI | 2/1/2025 | 17/6/2026 | Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx. | |
| Aplazada | Alta (7.1) | 0.33% | — | Saoshyant1994 Saoshyant ElementAI | 18/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saoshyant1994 Saoshyant Element saoshyant-element allows Reflected XSS.This issue affects Saoshyant Element: from n/a through <= 1.2. | |
| Analizada | Alta (7.8) | 0.54% | — | Adobe Photoshop | 10/12/2024 | 17/6/2026 | Photoshop Desktop versions 26.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (7.5) | 0.72% | — | Sharp MFPAIToshibatec MFPAI | 26/11/2024 | 17/6/2026 | Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition. | |
| Aplazada | Alta (7.4) | 0.53% | — | Sharp Corporation MFPAIToshiba Tech Corporation MFPAI | 26/11/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and… | |
| Aplazada | Alta (7.1) | 0.41% | — | Josh Kohlbach Jigoshop - Store ExporterAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Jigoshop – Store Exporter jigoshop-exporter allows Reflected XSS.This issue affects Jigoshop – Store Exporter: from n/a through <= 1.5.8. | |
| Aplazada | Media (6.5) | 0.24% | — | Santhosh Veer Stylish Internal LinksAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Santhosh veer Stylish Internal Links stylish-internal-links allows DOM-Based XSS.This issue affects Stylish Internal Links: from n/a through <= 1.9. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Bikramjoshii B-banner-sliderAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in bikramjoshii B-Banner Slider b-banner-slider allows Upload a Web Shell to a Web Server.This issue affects B-Banner Slider: from n/a through <= 1.1. | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Photoshop | 12/11/2024 | 17/6/2026 | Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Crítica (10) | 1.5% | 💥 PoC | Joshua Wolfe THE Novel Design Store DirectoryAI | 11/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Michael Visser Jigoshop Store ToolkitAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Visser Jigoshop – Store Toolkit jigoshop-store-toolkit allows Reflected XSS.This issue affects Jigoshop – Store Toolkit: from n/a through <= 1.4.0. | |
| Analizada | Media (5.4) | 0.26% | — | Joshlobe Ultimate Tinymce | 30/10/2024 | 17/6/2026 | The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… |