Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.22% | — | Opentext UcmdbAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The vulnerability could allow an attacker has high level access to UCMDB to create or update data with malicious scripts This issue affects uCMDB: 24.4. | |
| Aplazada | Media (6.8) | 0.24% | — | Mendix RichtextAI | 17/11/2025 | 17/6/2026 | A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not properly neutralize the input. This could allow an attacker to execute cross-site scripting attacks. | |
| Aplazada | Media (4.3) | 0.18% | — | ALT Text Generator AIAI | 12/11/2025 | 17/6/2026 | The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the atgai_delete_api_key() function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.27% | 💥 PoC | Sublime HQ PTY LTD Sublime TextAI | 10/11/2025 | 17/6/2026 | An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because replacing the uninstall file requires… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Oobabooga Text-generation-webuiAI | 6/11/2025 | 17/6/2026 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Oobabooga Text-generation-webuiAI | 6/11/2025 | 17/6/2026 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Alta (8.2) | 0.35% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 6/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.5. | |
| Aplazada | Media (6.1) | 0.16% | — | SH Contextual HelpAI | 4/11/2025 | 17/6/2026 | The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation in the sh_contextual_help_dashboard_widget() function. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Analizada | Media (5.3) | 0.29% | — | Opentext Flipper | 21/10/2025 | 17/6/2026 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2. | |
| Analizada | Baja (1) | 0.36% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | SQL Injection vulnerability in opentext Flipper allows SQL Injection. The vulnerability could allow a low privilege user to interact with the database in unintended ways and extract data by interacting with the HQL processor. This issue affects Flipper: 3.1.2. | |
| Analizada | Media (5.3) | 0.39% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2. | |
| Analizada | Baja (2.3) | 0.28% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low-privilege user to elevate privileges within the application. This issue affects Flipper: 3.1.2. | |
| Analizada | Media (5.3) | 0.29% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local file path and then download the specified file from the system by requesting the stored document ID. This issue affects Flipper: 3.1.2. | |
| Analizada | Baja (1) | 0.26% | — | Opentext Flipper | 20/10/2025 | 1/10/2026 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low privilege user to interact with the backend API without sufficient privileges. This issue affects Flipper: 3.1.2. | |
| Aplazada | Media (6.4) | 0.24% | — | Dhivehi TextAI | 15/10/2025 | 17/6/2026 | The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.2) | 0.57% | — | Text-generation-webuiAI | 13/10/2025 | 17/6/2026 | text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. When the application processes… | |
| Aplazada | Alta (7.5) | 0.51% | — | Langchain-text-splittersAILxmlAI | 6/10/2025 | 17/6/2026 | The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse() and lxml.etree.XSLT() without any… | |
| Aplazada | Media (4.3) | 0.20% | 💥 PoC | Trinityaudio Text TO SpeechAI | 4/10/2025 | 17/6/2026 | The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.20.2. This is due to missing or incorrect nonce validation in the '/admin/inc/post-management.php' file. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.18% | — | TextbuilderAI | 3/10/2025 | 17/6/2026 | The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validation on the 'handleToken' function. This makes it possible for unauthenticated attackers to update a user's authorization token via a forged request granted they… | |
| Aplazada | Media (6.5) | 0.34% | — | WP Cycle Text AnnouncementAI | 3/10/2025 | 17/6/2026 | The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all versions up to, and including, 8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.46% | — | Textit Phonenumbers | 27/9/2025 | 17/6/2026 | Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range". | |
| Aplazada | Media (4.3) | 0.24% | — | Azizul Hasan Text TO Speech TTS AccessibilityAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Azizul Hasan Text To Speech TTS Accessibility text-to-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Text To Speech TTS Accessibility: from n/a through <= 1.9.30. | |
| Analizada | Alta (7.5) | 0.34% | — | Mariadb Model Context Protocol | 10/9/2025 | 17/6/2026 | An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation. | |
| Aplazada | Media (6.5) | 0.17% | — | Silverplugins217 Dynamic Text Field FOR Contact Form 7AI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Dynamic Text Field For Contact Form 7 dynamic-text-field-for-contact-form-7 allows Stored XSS.This issue affects Dynamic Text Field For Contact Form 7: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.17% | — | W1zzard Simple Text SliderAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Text Slider simple-text-slider allows Stored XSS.This issue affects Simple Text Slider: from n/a through <= 1.0.5. |