Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.29% | — | Woocommerce HSS Extension FOR Streaming VideoAI | 7/1/2025 | 17/6/2026 | The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘videolink’ parameter in all versions up to, and including, 3.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.34% | — | Maintenance Coming Soon Redirect AnimationAI | 20/12/2024 | 17/6/2026 | The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option',… | |
| Aplazada | Media (5.4) | 0.22% | — | Chenyenming UI Slider Filter BY PriceAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allows Cross Site Request Forgery.This issue affects Ui Slider Filter By Price: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.20% | — | Projectcaruso Flaming FormsAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in jcaruso001 Flaming Forms flaming-forms allows Stored XSS.This issue affects Flaming Forms: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.52% | — | 8degreethemes Coming Soon Landing Page AND Maintenance ModeAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress Plugin allows Retrieve Embedded Sensitive Data.This issue affects Coming Soon Landing Page and Maintenance Mode WordPress Plugin: from n/a through 2.2.0. | |
| Modificada | Media (5.3) | 0.37% | — | Rstheme Ultimate Coming Soon & Maintenance | 6/12/2024 | 17/6/2026 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to change the template used… | |
| Modificada | Media (4.3) | 0.34% | — | Rstheme Ultimate Coming Soon & Maintenance | 6/12/2024 | 17/6/2026 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (7.5) | 0.51% | — | GaminghubAI | 3/12/2024 | 17/6/2026 | Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity. | |
| Aplazada | Media (4.3) | 0.40% | — | GaminghubAI | 3/12/2024 | 17/6/2026 | Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview. | |
| Aplazada | Media (6.5) | 0.46% | — | GaminghubAI | 3/12/2024 | 17/6/2026 | Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview. | |
| Analizada | Media (6.9) | 1.4% | 💥 PoC | Qnap Media Streaming Add-on | 22/11/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 )… | |
| Analizada | Media (6.9) | 0.71% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file. | |
| Analizada | Alta (8.2) | 1.00% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file. | |
| Analizada | Media (5.1) | 0.75% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system. | |
| Analizada | Alta (8.7) | 0.66% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts. | |
| Analizada | Crítica (9.4) | 0.50% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. | |
| Aplazada | Media (6.1) | 0.27% | — | WIP Incoming LiteAI | 21/11/2024 | 17/6/2026 | The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the save_option() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Modificada | Alta (8.8) | 0.55% | — | Incsub Hummingbird | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1. | |
| Aplazada | Media (5.9) | 0.27% | — | Seedprod Coming Soon Page Under Construction Maintenance ModeAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Stored XSS.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <=… | |
| Analizada | Alta (7.8) | 0.27% | — | Electronics.jtekt Kostac PLC Programming Software | 3/10/2024 | 17/6/2026 | Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service… | |
| Analizada | Alta (8.1) | 0.81% | — | Mingsoft Mcms | 3/9/2024 | 17/6/2026 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. | |
| Analizada | Media (6.1) | 0.35% | — | Projectcaruso Flaming Forms | 2/9/2024 | 17/6/2026 | The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6.1) | 0.38% | — | Projectcaruso Flaming Forms | 2/9/2024 | 17/6/2026 | The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators. | |
| Aplazada | Baja (3.7) | 0.36% | — | Ilyasine Maintenance AND Coming Soon Redirect AnimationAI | 29/8/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through <= 2.3.3. | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. |