Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.29% | — | Ajay Contextual Related PostsAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Contextual Related Posts contextual-related-posts allows DOM-Based XSS.This issue affects Contextual Related Posts: from n/a through <= 4.0.2. | |
| Aplazada | Media (6.1) | 0.18% | — | Advanced Reorder Image Text SliderAI | 3/5/2025 | 17/6/2026 | The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'reorder-simple-image-text-slider-setting' page. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Baja (2.1) | 0.22% | — | Opentext Digital Asset ManagementAI | 28/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. This issue affects Digital Asset Management.: through 24.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Webplanetsoft Inline Text PopupAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webplanetsoft Inline Text Popup inline-text-popup allows DOM-Based XSS.This issue affects Inline Text Popup: from n/a through <= 1.0.0. | |
| Modificada | Alta (8.8) | 0.28% | — | Alttext ALT Text AI | 22/4/2025 | 17/6/2026 | Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.9.93. | |
| Modificada | Media (4.8) | 0.23% | — | Textmetrics | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2. | |
| Aplazada | Media (5.9) | 0.34% | — | Opentext Content ManagementAI | 21/4/2025 | 17/6/2026 | User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes. | |
| Aplazada | Baja (2.3) | 0.44% | — | Opentext Arcsight Enterprise Security ManagerAI | 21/4/2025 | 17/6/2026 | Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. | |
| Aplazada | Media (5.7) | 0.39% | — | Opentext Content ManagementAI | 21/4/2025 | 17/6/2026 | Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system. | |
| Aplazada | Media (5.5) | 0.29% | — | Opentext Content ServerAI | 21/4/2025 | 17/6/2026 | Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4. | |
| Aplazada | Media (6.5) | 0.31% | — | Elliot Sowersby AI Text TO SpeechAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Elliot Sowersby / RelyWP AI Text to Speech ai-text-to-speech allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Text to Speech: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7) | 0.19% | — | Opentext Secure Content ManagerAI | 17/4/2025 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.This issue affects Secure Content Manager: 23.4. End-users can potentially exploit the vulnerability to execute malicious code in the trusted context of the thick-client application. | |
| Aplazada | Alta (8.7) | 0.33% | — | Opentext Operations Bridge ManagerAIOpentext Operations Bridge SuiteAIOpentext UcmdbAI | 17/4/2025 | 17/6/2026 | Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite (Containerized), OpenText™ UCMDB ( Classic and Containerized) allows Privilege Escalation. The vulnerability could allow authenticated attackers to elevate user privileges. This issue affects… | |
| Aplazada | Alta (7.2) | 0.41% | — | Sonicwall NetextenderAI | 10/4/2025 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths. | |
| Aplazada | Alta (7.2) | 0.37% | — | Sonicwall NetextenderAI | 10/4/2025 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion. | |
| Aplazada | Alta (7.2) | 0.35% | — | Sonicwall NetextenderAI | 10/4/2025 | 17/6/2026 | An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker to modify configurations. | |
| Aplazada | Media (4.3) | 0.29% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 10/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Retrieve Embedded Sensitive Data.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.9. | |
| Aplazada | Media (5.4) | 0.49% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.34% | — | Matat Technologies Textme SMSAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Matat Technologies TextMe SMS textme-sms-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TextMe SMS: from n/a through <= 1.9.1. | |
| Aplazada | Media (6.5) | 0.38% | — | Richtexteditor Rich Text EditorAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.36% | — | Dejan HypotextAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEJAN Hypotext hypotext allows Stored XSS.This issue affects Hypotext: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.14% | — | Richtexteditor Rich Text EditorAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor richtexteditor allows Stored XSS.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.9) | 0.23% | — | Nazmur Rahman Text-selection-colorAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nazmur Rahman Text Selection Color text-selection-color allows Stored XSS.This issue affects Text Selection Color: from n/a through <= 1.6. | |
| Aplazada | Media (5.4) | 0.53% | — | TextmetricsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.1. | |
| Aplazada | Crítica (9.9) | 0.78% | — | Govind Visual Text EditorAI | 26/3/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.This issue affects Visual Text Editor: from n/a through <= 1.2.1. |