Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.46%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
ModificadaAlta (7.8)0.46%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
ModificadaAlta (7.8)0.46%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
ModificadaAlta (7.8)0.46%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.
ModificadaAlta (7.8)0.42%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
ModificadaAlta (7.8)0.46%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
ModificadaAlta (7.8)0.42%—Randygaul Cute PNG1/10/202417/6/2026
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
AnalizadaMedia (5.4)0.30%—Wp-brandtheme Preloader Plus7/9/202417/6/2026
The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
ModificadaMedia (4.8)0.26%—Wpmudev Branda22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Branda branda-white-labeling.This issue affects Branda: from n/a through <= 3.4.17.
AplazadaMedia (5.5)0.36%—WP Total BrandingAI12/7/202417/6/2026
The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.3)0.45%—Wpmudev Branda11/7/202417/6/2026
The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access to the files. This makes it possible for unauthenticated attackers to…
ModificadaCrítica (9.8)27%—Grandstream Gxp2135 Firmware3/7/202417/6/2026
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.
ModificadaMedia (5.4)0.31%—Wpmudev Branda21/6/202417/6/2026
The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (5.3)0.37%—Wpmudev BrandaAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in WPMU DEV Branda allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Branda: from n/a through 3.4.14.
AplazadaMedia (5.9)0.26%—Xabier Miranda WP Back ButtonAI3/6/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back Button: from n/a through 1.1.3.
AplazadaMedia (5.9)0.28%—Buffercode Random BannerAI2/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows DOM-Based XSS.This issue affects Random Banner: from n/a through <= 4.2.12.
AnalizadaMedia (5.5)0.20%—Mranderson Base64 Encoder/decoder15/5/202429/7/2026
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
AnalizadaBaja (2.4)0.22%—Mranderson Base64 Encoder/decoder15/5/202429/7/2026
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaMedia (4.8)0.75%💥 ExploitMranderson Base64 Encoder/decoder15/5/202429/7/2026
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaCrítica (9.8)0.60%—Fmemodules PreorderandnoticationAI29/4/202417/6/2026
SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.
AplazadaAlta (8.8)0.88%—Grandstream Ucm6202AIGrandstream Ucm6204AIGrandstream Ucm6208AIGrandstream Ucm6510AI29/4/202417/6/2026
The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected…
ModificadaMedia (5.4)0.35%—Hot-themes HOT Random Image27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hot Themes Hot Random Image allows Stored XSS.This issue affects Hot Random Image: from n/a through 1.8.1.
AplazadaAlta (8.8)0.39%—Grandstream Gxp14xxAIGrandstream Gxp16xxAI9/3/202417/6/2026
An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token.
ModificadaMedia (5.3)0.52%—Brandonwamboldt Wordpress Access Control28/2/202417/6/2026
The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when unset) and view restricted page and post…
ModificadaCrítica (9.8)0.52%—Mypresta Manufacturers (brands) Images Block19/1/202417/6/2026
In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
Orbitaley — Vulnerabilidades