Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.29%—Woocommerce HSS Extension FOR Streaming VideoAI7/1/202517/6/2026
The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘videolink’ parameter in all versions up to, and including, 3.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (4.3)0.34%—Maintenance Coming Soon Redirect AnimationAI20/12/202417/6/2026
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option',…
AplazadaMedia (5.4)0.22%—Chenyenming UI Slider Filter BY PriceAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allows Cross Site Request Forgery.This issue affects Ui Slider Filter By Price: from n/a through <= 1.1.
AplazadaAlta (7.1)0.20%—Projectcaruso Flaming FormsAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jcaruso001 Flaming Forms flaming-forms allows Stored XSS.This issue affects Flaming Forms: from n/a through <= 1.0.1.
AplazadaMedia (5.3)0.52%—8degreethemes Coming Soon Landing Page AND Maintenance ModeAI13/12/202417/6/2026
Missing Authorization vulnerability in 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress Plugin allows Retrieve Embedded Sensitive Data.This issue affects Coming Soon Landing Page and Maintenance Mode WordPress Plugin: from n/a through 2.2.0.
ModificadaMedia (5.3)0.37%—Rstheme Ultimate Coming Soon & Maintenance6/12/202417/6/2026
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to change the template used…
ModificadaMedia (4.3)0.34%—Rstheme Ultimate Coming Soon & Maintenance6/12/202417/6/2026
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaAlta (7.5)0.51%—GaminghubAI3/12/202417/6/2026
Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.
AplazadaMedia (4.3)0.40%—GaminghubAI3/12/202417/6/2026
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.
AplazadaMedia (6.5)0.46%—GaminghubAI3/12/202417/6/2026
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.
AnalizadaMedia (6.9)1.4%💥 PoCQnap Media Streaming Add-on22/11/202417/6/2026
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 )…
AnalizadaMedia (6.9)0.71%—Wowza Streaming Engine21/11/202417/6/2026
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file.
AnalizadaAlta (8.2)1.00%—Wowza Streaming Engine21/11/202417/6/2026
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file.
AnalizadaMedia (5.1)0.75%—Wowza Streaming Engine21/11/202417/6/2026
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.
AnalizadaAlta (8.7)0.66%—Wowza Streaming Engine21/11/202417/6/2026
Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.
AnalizadaCrítica (9.4)0.50%—Wowza Streaming Engine21/11/202417/6/2026
Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.
AplazadaMedia (6.1)0.27%—WIP Incoming LiteAI21/11/202417/6/2026
The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the save_option() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web…
ModificadaAlta (8.8)0.55%—Incsub Hummingbird1/11/202417/6/2026
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.
AplazadaMedia (5.9)0.27%—Seedprod Coming Soon Page Under Construction Maintenance ModeAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Stored XSS.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <=…
AnalizadaAlta (7.8)0.27%—Electronics.jtekt Kostac PLC Programming Software3/10/202417/6/2026
Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service…
AnalizadaAlta (8.1)0.81%—Mingsoft Mcms3/9/202417/6/2026
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
AnalizadaMedia (6.1)0.35%—Projectcaruso Flaming Forms2/9/202417/6/2026
The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (6.1)0.38%—Projectcaruso Flaming Forms2/9/202417/6/2026
The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.
AplazadaBaja (3.7)0.36%—Ilyasine Maintenance AND Coming Soon Redirect AnimationAI29/8/202417/6/2026
Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through <= 2.3.3.
AnalizadaAlta (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+34228/8/202417/6/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.