Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.27% | — | S3bubble-amazon-web-services-oembed-media-streaming-support | 11/3/2025 | 17/6/2026 | The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (7.1) | 0.37% | — | Chenyenming UI Slider Filter BY PriceAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allows Reflected XSS.This issue affects Ui Slider Filter By Price: from n/a through <= 1.1. | |
| Analizada | Media (6.5) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted SWF file. | |
| Analizada | Media (6.5) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted ABC file. | |
| Analizada | Media (6.5) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. | |
| Analizada | Media (6.5) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. | |
| Analizada | Media (6.5) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. | |
| Analizada | Media (6.5) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file. | |
| Analizada | Alta (8.2) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. | |
| Analizada | Alta (8.2) | 0.39% | — | Libming | 20/2/2025 | 17/6/2026 | A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8. | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Alta (7.1) | 0.31% | — | Hoststreamsell HSS Embed Streaming VideoAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoststreamsell HSS Embed Streaming Video hss-embed-streaming-video allows Reflected XSS.This issue affects HSS Embed Streaming Video: from n/a through <= 3.23. | |
| Analizada | Media (5.5) | 0.19% | — | Hummingheads Defense Platform | 6/2/2025 | 17/6/2026 | Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of… | |
| Analizada | Media (5.5) | 0.15% | — | Hummingheads Defense Platform | 6/2/2025 | 17/6/2026 | NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of Death (BSOD), and as a result, cause a… | |
| Analizada | Alta (8.8) | 0.19% | — | Hummingheads Defense Platform | 6/2/2025 | 17/6/2026 | Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system where the product is running may be obtained. | |
| Analizada | Alta (8.8) | 0.14% | — | Hummingheads Defense Platform | 6/2/2025 | 17/6/2026 | Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary… | |
| Analizada | Alta (8.8) | 0.15% | — | Hummingheads Defense Platform | 6/2/2025 | 17/6/2026 | Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege. | |
| Analizada | Alta (8.8) | 0.18% | — | Hummingheads Defense Platform | 6/2/2025 | 17/6/2026 | Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system where the product is running may be obtained. | |
| Aplazada | Media (4.3) | 0.16% | — | Seedprod Coming Soon Page Under Construction AND Maintenance ModeAI | 27/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Cross Site Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.18.9. | |
| Modificada | Media (5.4) | 0.21% | — | Rstheme Ultimate Coming Soon & Maintenance | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Coming Soon & Maintenance: from n/a through <= 1.0.9. | |
| Modificada | Media (4.3) | 0.22% | — | Rstheme Ultimate Coming Soon & Maintenance | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Coming Soon & Maintenance: from n/a through <= 1.0.9. | |
| Aplazada | Alta (8.6) | 0.19% | — | Adobe Flash Programming UtilityAI | 24/1/2025 | 17/6/2026 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Aplazada | Alta (7.1) | 0.26% | — | Suryabhan Custom Coming SoonAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SuryaBhan Custom Coming Soon custom-coming-soon allows Reflected XSS.This issue affects Custom Coming Soon: from n/a through <= 2.2. | |
| Analizada | Media (5.4) | 0.22% | — | Videowhisper Live Streaming Integration | 23/1/2025 | 17/6/2026 | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (5.9) | 0.38% | — | Yesstreamingdev Shoutcast AND Icecast Html5 WEB Radio PlayerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yesstreamingdev Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com allows Stored XSS.This issue affects Shoutcast and Icecast HTML5 Web… |