Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.16% | — | Opentext Service ManagerAI | 12/3/2025 | 17/6/2026 | Unquoted Search Path or Element vulnerability in OpenText™ Service Manager. The vulnerability could allow a user to gain SYSTEM privileges through Privilege Escalation. This issue affects Service Manager: 9.70, 9.71, 9.72. | |
| Aplazada | Baja (2.1) | 0.32% | — | Opentext Service ManagerAI | 12/3/2025 | 17/6/2026 | Improper Neutralization of Script in an Error Message Web Page vulnerability in OpenText™ Service Manager. The vulnerability could reveal sensitive information retained by the browser. This issue affects Service Manager: 9.70, 9.71, 9.72, 9.80. | |
| Aplazada | Crítica (10) | 0.39% | — | Opentext Identity Manager Advanced EditionAI | 5/3/2025 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager… | |
| Aplazada | Alta (7.1) | 0.39% | — | Adrian Vaquez ContextoAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Vaquez Contexto contexto allows Reflected XSS.This issue affects Contexto: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.37% | — | Yashar Texteller TextellerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yashar Texteller texteller allows Reflected XSS.This issue affects Texteller: from n/a through <= 1.3.0. | |
| Aplazada | Media (6.5) | 0.26% | — | GAL OP WP Responsive Slab TextAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gal_op WP Responsive Auto Fit Text wp-responsive-slab-text allows DOM-Based XSS.This issue affects WP Responsive Auto Fit Text: from n/a through <= 0.2. | |
| Aplazada | Media (6.5) | 0.41% | — | Bplugins Animated Text BlockAI | 24/2/2025 | 17/6/2026 | Missing Authorization vulnerability in bPlugins Animated Text Block animated-text-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animated Text Block: from n/a through <= 1.0.7. | |
| Aplazada | Media (6.5) | 0.28% | — | Garrettgrimm Simple Select ALL Text BOXAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simple Select All Text Box simple-select-all-text-box allows Stored XSS.This issue affects Simple Select All Text Box: from n/a through <= 3.2. | |
| Aplazada | Media (5.4) | 0.28% | — | Opentext Content ManagementAI | 4/2/2025 | 17/6/2026 | Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system. This… | |
| Aplazada | Media (6.5) | 0.26% | 💥 PoC | Enflick TextnowAI | 3/2/2025 | 17/6/2026 | The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component. | |
| Modificada | Media (6.1) | 0.40% | — | Wpmessiah AI Image ALT Text Generator FOR WP | 30/1/2025 | 17/6/2026 | The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.5) | 0.20% | — | Sonicwall NetextenderAI | 30/1/2025 | 17/6/2026 | A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation. | |
| Aplazada | Media (6.5) | 0.35% | — | Linnea Huxford Blur TextAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford Blur Text blur-text allows Stored XSS.This issue affects Blur Text: from n/a through <= 1.0.0. | |
| Aplazada | Alta (8.2) | 0.39% | — | Opentext Solutions Business ManagerAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Solutions Business Manager (SBM) allows Stored XSS. The vulnerability could result in the exposure of private information to an unauthorized actor. This issue affects Solutions Business Manager (SBM):… | |
| Modificada | Media (5.4) | 0.30% | — | Wpdeveloper Typing Text | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Typing Text typing-text allows Stored XSS.This issue affects Typing Text: from n/a through <= 1.2.7. | |
| Aplazada | Media (4.3) | 0.15% | — | Sevenspark Contact Form 7 Dynamic Text ExtensionAI | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Cross Site Request Forgery.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.1. | |
| Aplazada | Media (6.4) | 0.35% | — | Text PrompterAI | 24/12/2024 | 17/6/2026 | The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Alta (8) | 0.38% | — | Opentext Privileged Access ManagerAI | 19/12/2024 | 17/6/2026 | In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5) | |
| Aplazada | Media (5.3) | 0.50% | — | Opentext Operations Bridge ManagerAI | 19/12/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation. The vulnerability could be exploited to confidential information This issue affects Operations Bridge Manager: 2017.05, 2017.11, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05,… | |
| Aplazada | Media (6.4) | 0.35% | — | Gopiplus WP Photo Text Slider 50AI | 14/12/2024 | 17/6/2026 | The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo-slider' shortcode in all versions up to, and including, 8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.54% | — | Rextheme Change Woocommerce ADD TO Cart Button TextAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Rextheme Change WooCommerce Add To Cart Button Text allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Change WooCommerce Add To Cart Button Text: from n/a through 1.3. | |
| Aplazada | Media (6.1) | 0.36% | — | Quran Multilanguage Text AudioAI | 10/12/2024 | 17/6/2026 | The Quran multilanguage Text & Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sourate' and 'lang' parameter in all versions up to, and including, 2.3.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.47% | — | Inisev Enhanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in cl272 Enhanced Text Widget enhanced-text-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through <= 1.6.3. | |
| Aplazada | Media (5.4) | 0.48% | — | Matat Technologies Textme SMSAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Matat Technologies TextMe SMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TextMe SMS: from n/a through 1.9.0. | |
| Aplazada | Media (5.3) | 0.44% | — | MAX Chirkov Advanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Max Chirkov Advanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Text Widget : from n/a through 2.1.2. |