Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Bobbingwide OIKAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions. | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Bing Search | 14/7/2026 | 24/7/2026 | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.3) | 0.80% | — | AutobingumiAI | 2/7/2026 | 14/7/2026 | AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can… | |
| Aplazada | Crítica (9.8) | 0.39% | — | PlumbingAI | 17/6/2026 | 30/9/2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | |
| Analizada | Media (4.3) | 0.70% | — | Microsoft Bing | 9/6/2026 | 23/7/2026 | User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 1.5% | — | Microsoft Bing | 23/4/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Bing | 3/4/2026 | 24/7/2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microsoft Bing Images | 19/3/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microsoft Bing Images | 19/3/2026 | 17/6/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.80% | — | Microsoft Bing | 19/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (6.1) | 0.27% | — | Httpbingo Go-httpbin | 2/1/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Aplazada | Media (6.5) | 0.20% | — | Bobbingwide OIKAI | 9/12/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows DOM-Based XSS.This issue affects oik: from n/a through <= 4.15.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | Bingu ReplymailAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail replymail allows Stored XSS.This issue affects replyMail: from n/a through <= 1.2.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Bobbingwide Oik-privacy-policyAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik-privacy-policy oik-privacy-policy allows Reflected XSS.This issue affects oik-privacy-policy: from n/a through <= 1.4.10. | |
| Aplazada | Alta (7.1) | 0.24% | — | Bobbingwide OIKAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows Reflected XSS.This issue affects oik: from n/a through <= 4.15.2. | |
| Aplazada | Media (4.3) | 0.14% | — | Bobbingwide OIKAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide oik oik allows Cross Site Request Forgery.This issue affects oik: from n/a through <= 4.15.2. | |
| Aplazada | Media (5.3) | 0.34% | — | Bobbingwide OIKAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in bobbingwide oik oik allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects oik: from n/a through <= 4.15.1. | |
| Analizada | Crítica (9.8) | 1.7% | — | Microsoft Bing | 19/2/2025 | 17/6/2026 | Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network | |
| Aplazada | Alta (7.1) | 0.27% | — | Askewbrook Bing Search API IntegrationAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in askewbrook Bing Search API Integration abbs-bing-search allows Reflected XSS.This issue affects Bing Search API Integration: from n/a through <= 0.3.3. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Xaraartech External Featured Image From BingAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-featured-image-from-bing allows Upload a Web Shell to a Web Server.This issue affects External featured image from bing: from n/a through <= 1.0.2. | |
| Analizada | Media (4.3) | 0.18% | — | Bobbingwide OIK | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0. | |
| Aplazada | Media (6.4) | 0.34% | — | Bobbingwide OIKAI | 9/7/2024 | 17/6/2026 | The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bw_button shortcode in all versions up to, and including, 4.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level… | |
| Analizada | Media (5.4) | 0.73% | — | Microsoft Bing Search | 14/5/2024 | 17/6/2026 | Microsoft Bing Search Spoofing Vulnerability | |
| Modificada | Media (5.4) | 0.40% | — | Bobbingwide OIK | 14/3/2024 | 17/6/2026 | The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact_button and bw_button shortcodes in all versions up to, and including, 4.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.21% | — | Dan009 WP Bing MAP PRO | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions. |