Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 0.40% | — | Discord LibdaveAI | 2/10/2026 | 2/10/2026 | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected… | |
| Aplazada | Media (5.3) | 0.18% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels… | |
| Aplazada | Media (6) | 0.28% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured… | |
| Aplazada | Alta (8.2) | 0.20% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity… | |
| Aplazada | Media (4.1) | 0.16% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of… | |
| Aplazada | Alta (8.1) | 0.46% | — | Miniorange Discord IntegrationAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | |
| Aplazada | Alta (7.3) | 0.39% | — | Discord ClientAI | 23/1/2026 | 17/6/2026 | Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Aplazada | Alta (7.1) | 0.26% | — | Expresstechsoftware Memberpress Discord AddonAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon expresstechsoftwares-memberpress-discord-add-on allows Reflected XSS.This issue affects MemberPress Discord Addon: from n/a through <= 1.1.4. | |
| Aplazada | Media (4.3) | 0.29% | — | DiscordAI | 22/1/2026 | 13/9/2026 | Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is… | |
| Aplazada | Media (5.3) | 0.21% | — | WP Discord Post PlusAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2. | |
| Aplazada | Crítica (9.1) | 0.36% | — | Mediawiki DiscordnotificationsAI | 10/7/2025 | 17/6/2026 | DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and file_get_contents to arbitrary URLs set via $wgDiscordIncomingWebhookUrl and $wgDiscordAdditionalIncomingWebhookUrls. This allows for DOS… | |
| Aplazada | Alta (8.1) | 0.64% | — | Miniorange Discord IntegrationAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integration miniorange-discord-integration allows PHP Local File Inclusion.This issue affects miniOrange Discord Integration: from n/a through <= 2.2.2. | |
| Analizada | Alta (7.3) | 0.32% | — | Discord | 10/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue is some unknown functionality in the library WINSTA.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is rather high.… | |
| Aplazada | Media (5.9) | 0.27% | — | Sarveshmrao WP Discord InviteAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarvesh M Rao WP Discord Invite wp-discord-invite allows Stored XSS.This issue affects WP Discord Invite: from n/a through <= 2.5.3. | |
| Aplazada | Alta (7.1) | 0.29% | — | Expresstechsoftware Memberpress Discord AddonAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon expresstechsoftwares-memberpress-discord-add-on allows Reflected XSS.This issue affects MemberPress Discord Addon: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | Nicola Mustone WP Discord PostAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicola Mustone WP Discord Post wp-discord-post allows Reflected XSS.This issue affects WP Discord Post: from n/a through <= 2.1.0. | |
| Aplazada | Alta (8.3) | 0.36% | — | Discord BOT Framework KernelAI | 18/2/2025 | 17/6/2026 | Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By… | |
| Aplazada | Baja (2) | 0.17% | — | DiscordAI | 27/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of an attack is rather… | |
| Aplazada | Media (5.3) | 0.41% | — | Red-discord-bot REDAI | 11/7/2024 | 17/6/2026 | Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional permission controls may authorize a user to run a command even when that user doesn't have permissions to manage a channel. None of the core commands… | |
| Aplazada | Alta (7.5) | 0.60% | — | Discordjs OpusAI | 10/7/2024 | 17/6/2026 | All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a system crash. | |
| Modificada | Crítica (9.8) | 1.8% | — | Discord | 28/1/2024 | 17/6/2026 | An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. | |
| Modificada | Media (6.5) | 0.33% | — | Sarveshmrao WP Discord Invite | 17/1/2024 | 17/6/2026 | The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request. | |
| Modificada | Alta (8.8) | 1.5% | — | Demon1a Discord-recon | 9/1/2024 | 17/6/2026 | Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in… | |
| Modificada | Media (4.8) | 0.40% | — | Sarveshmrao WP Discord Invite | 6/11/2023 | 17/6/2026 | The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 0.49% | — | Vaerys-dawn Discordsailv2 | 6/11/2023 | 17/6/2026 | A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The name of the patch is… |