Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
1231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.29% | — | AngularCkeditor5 | 7/11/2025 | 17/6/2026 | Una vulnerabilidad reflejada de cross-site scripting (XSS) en CKeditor v46.1.0 y Angular v18.0.0 permite a los atacantes ejecutar código arbitrario en el contexto del navegador de un usuario mediante la inyección de una carga útil manipulada. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Content Editor FOR Specific TemplateAI | 24/10/2025 | 8/10/2026 | El plugin Disable Content Editor For Specific Template para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 2.0, inclusive. Esto se debe a la falta de validación de nonce en las actualizaciones de configuración de plantillas. Esto hace posible que atacantes no… | |
| Aplazada | Alta (8.8) | 0.40% | — | Themeeditor Theme EditorAI | 18/10/2025 | 25/9/2026 | El plugin Theme Editor para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 3.0, inclusive. Esto se debe a una validación de nonce ausente o incorrecta en la página 'theme_editor_theme'. Esto hace posible que atacantes no autenticados logren la ejecución remota de código a través… | |
| Analizada | Alta (7.4) | 0.64% | 💥 PoC | Unity Editor | 3/10/2025 | 17/6/2026 | Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code… | |
| Aplazada | Media (5.9) | 0.38% | — | Managefy File Manager Code Editor AND BackupAI | 1/10/2025 | 17/6/2026 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and full paths to backup… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpfront User Role EditorAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor wpfront-user-role-editor allows Stored XSS.This issue affects WPFront User Role Editor: from n/a through <= 4.2.3. | |
| Aplazada | Baja (1.9) | 0.27% | — | Changsha Developer Technology Iview EditorAI | 25/9/2025 | 17/6/2026 | A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was… | |
| Analizada | Media (6.5) | 0.32% | — | Open-federation Json-schema-editor-visual | 24/9/2025 | 17/6/2026 | json-schema-editor-visual es un paquete que proporciona un editor de jsonschema. Una vulnerabilidad de Contaminación de Prototipos en la función setData y deleteData de las versiones de json-schema-editor-visual hasta la 1.1.1 permite a los atacantes inyectar o eliminar propiedades en Object.prototype mediante el… | |
| Aplazada | Media (6.5) | 0.27% | — | Vwthemes Ibtana Visual EditorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VW THEMES Ibtana ibtana-visual-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through <= 1.2.5.3. | |
| Aplazada | Media (6.5) | 0.20% | — | Image-editor-by-pixoAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ickata Image Editor by Pixo image-editor-by-pixo allows DOM-Based XSS.This issue affects Image Editor by Pixo: from n/a through <= 2.3.8. | |
| Aplazada | Media (6.5) | 0.45% | — | Rouergue Creation Editor Custom Color PaletteAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Rouergue Création Editor Custom Color Palette editor-custom-color-palette allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editor Custom Color Palette: from n/a through <= 3.5.6. | |
| Aplazada | Media (6.4) | 0.24% | — | Admin Menu EditorAI | 6/9/2025 | 17/6/2026 | The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Media (4.3) | 0.14% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce allows Cross Site Request Forgery.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through <= 1.3.4. | |
| Aplazada | Baja (2.3) | 0.42% | — | Ckeditor5AICkeditor5-clipboardAI | 4/9/2025 | 17/6/2026 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript… | |
| Analizada | Alta (7.8) | 0.18% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.25% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.25% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.26% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Aplazada | Media (4.3) | 0.14% | — | Wptableeditor Table EditorAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wptableeditor Table Editor wp-table-editor allows Cross Site Request Forgery.This issue affects Table Editor: from n/a through <= 1.6.4. | |
| Aplazada | Media (4.9) | 0.50% | 💥 PoC | Managefy File Manager Code Editor AND BackupAI | 28/8/2025 | 17/6/2026 | El complemento File Manager, Code Editor, and Backup by Managefy para WordPress es vulnerable a la Path Traversal en todas las versiones hasta la 1.4.8 incluida, mediante la función ajax_downloadfile(). Esto permite a atacantes autenticados, con acceso de suscriptor o superior, realizar acciones en archivos fuera del… | |
| Aplazada | Baja (1.9) | 0.27% | — | ZencartAICkeditorAI | 18/8/2025 | 17/6/2026 | Se detectó una vulnerabilidad en ZenCart 2.1.0. Esta vulnerabilidad afecta a una funcionalidad desconocida del componente CKEditor. La manipulación provoca Cross-Site Scripting. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado. La existencia real de esta vulnerabilidad aún… |