Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2779 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Mediavine CreateAI | 23/7/2026 | 18/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0. | |
| Aplazada | Alta (8.2) | 0.32% | — | MediacmsAI | 21/7/2026 | 30/9/2026 | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other users by adding arbitrary media tokens to their own playlist without access control checks. Attackers can issue a PUT request to the playlist API endpoint with a known… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Themexpert JmediaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS. | |
| Aplazada | Media (5.1) | 0.39% | — | Themexpert JmediaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Themexpert JmediaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits. | |
| Aplazada | Media (5.5) | 0.43% | — | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display SystemAI | 20/7/2026 | 20/7/2026 | A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. The manipulation of the argument Structure_ID results in… | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Media Encoder | 14/7/2026 | 28/8/2026 | Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Media Encoder | 14/7/2026 | 28/8/2026 | Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.26% | — | Adobe Media Encoder | 14/7/2026 | 28/8/2026 | Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Media Encoder | 14/7/2026 | 28/8/2026 | Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Media Encoder | 14/7/2026 | 28/8/2026 | Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (7.7) | 1.1% | — | ApacheAILaravel MediableAI | 13/7/2026 | 15/7/2026 | Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in… | |
| Aplazada | Media (5.3) | 0.36% | — | Laravel MediableAI | 13/7/2026 | 14/7/2026 | Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymous users to execute arbitrary JavaScript by uploading unsanitized SVG files containing embedded scripts in onload event handlers, script tags, or foreignObject elements. Attackers can store persistent… | |
| Aplazada | Alta (8.7) | 1.0% | — | Laravel MediableAI | 13/7/2026 | 14/7/2026 | Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the directory argument passed to MediaUploader::toDestination(). Attackers can exploit the permissive character-class regex that… | |
| Aplazada | Media (5.3) | 0.42% | — | Laravel MediableAI | 13/7/2026 | 15/7/2026 | Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). Attackers can craft URLs targeting RFC-1918 addresses,… | |
| Aplazada | Alta (8.3) | 0.52% | — | Quram Libimagecodec.mediaAI | 10/7/2026 | 10/7/2026 | Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. | |
| Aplazada | Alta (8.3) | 0.52% | 💥 PoC | Qualcomm Libimagecodec.media.quramAI | 10/7/2026 | 10/7/2026 | Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. | |
| Aplazada | Media (6.5) | 0.38% | — | Rtcamp RtmediaAI | 10/7/2026 | 10/7/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Alta (7.2) | 1.1% | — | Post Export Import With MediaAI | 10/7/2026 | 10/7/2026 | The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in… | |
| Aplazada | Alta (8.7) | 0.39% | 💥 PoC | Najeebmedia Frontend File ManagerAI | 7/7/2026 | 7/7/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the… | |
| En análisis | Media (6.9) | 0.52% | — | Mediawiki Cargo | 1/7/2026 | 7/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4. | |
| Analizada | Media (6.9) | 0.33% | — | Mediawiki | 1/7/2026 | 10/7/2026 | Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4. | |
| Analizada | Media (6.9) | 0.30% | — | Mediawiki | 1/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Charts Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Charts Extension: from * before 1.43.9,1.44.6,1.45.4. | |
| En análisis | Media (6.9) | 0.47% | — | Mediawiki Cargo | 1/7/2026 | 7/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4. | |
| Analizada | Media (6.9) | 0.28% | — | Mediawiki | 1/7/2026 | 9/7/2026 | URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4. |