Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.27% | — | AngularCkeditor5 | 7/11/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Content Editor FOR Specific TemplateAI | 24/10/2025 | 17/6/2026 | The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible for unauthenticated attackers to add or delete template… | |
| Aplazada | Alta (8.8) | 0.40% | — | Themeeditor Theme EditorAI | 18/10/2025 | 25/9/2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution via a forged request… | |
| Analizada | Alta (7.4) | 0.64% | 💥 PoC | Unity Editor | 3/10/2025 | 17/6/2026 | Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code… | |
| Aplazada | Media (5.9) | 0.38% | — | Managefy File Manager Code Editor AND BackupAI | 1/10/2025 | 17/6/2026 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and full paths to backup… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpfront User Role EditorAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront User Role Editor wpfront-user-role-editor allows Stored XSS.This issue affects WPFront User Role Editor: from n/a through <= 4.2.3. | |
| Aplazada | Baja (1.9) | 0.27% | — | Changsha Developer Technology Iview EditorAI | 25/9/2025 | 17/6/2026 | A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was… | |
| Analizada | Media (6.5) | 0.32% | — | Open-federation Json-schema-editor-visual | 24/9/2025 | 17/6/2026 | json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers to inject or delete properties on Object.prototype via supplying a crafted payload, causing denial of… | |
| Aplazada | Media (6.5) | 0.27% | — | Vwthemes Ibtana Visual EditorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VW THEMES Ibtana ibtana-visual-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ibtana: from n/a through <= 1.2.5.3. | |
| Aplazada | Media (6.5) | 0.20% | — | Image-editor-by-pixoAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ickata Image Editor by Pixo image-editor-by-pixo allows DOM-Based XSS.This issue affects Image Editor by Pixo: from n/a through <= 2.3.8. | |
| Aplazada | Media (6.5) | 0.45% | — | Rouergue Creation Editor Custom Color PaletteAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Rouergue Création Editor Custom Color Palette editor-custom-color-palette allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editor Custom Color Palette: from n/a through <= 3.5.6. | |
| Aplazada | Media (6.4) | 0.24% | — | Admin Menu EditorAI | 6/9/2025 | 17/6/2026 | The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Media (4.3) | 0.14% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce allows Cross Site Request Forgery.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through <= 1.3.4. | |
| Aplazada | Baja (2.3) | 0.42% | — | Ckeditor5AICkeditor5-clipboardAI | 4/9/2025 | 17/6/2026 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript… | |
| Analizada | Alta (7.8) | 0.18% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.25% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.25% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.26% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Aplazada | Media (4.3) | 0.14% | — | Wptableeditor Table EditorAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wptableeditor Table Editor wp-table-editor allows Cross Site Request Forgery.This issue affects Table Editor: from n/a through <= 1.6.4. | |
| Aplazada | Media (4.9) | 0.50% | 💥 PoC | Managefy File Manager Code Editor AND BackupAI | 28/8/2025 | 17/6/2026 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of… | |
| Aplazada | Baja (1.9) | 0.27% | — | ZencartAICkeditorAI | 18/8/2025 | 17/6/2026 | A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this… |