Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.24% | — | Wpdeveloper EmbedpressAI | 30/9/2026 | 30/9/2026 | The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Aplazada | Media (6.8) | 0.24% | — | Wpdeveloper EmbedpressAI | 27/9/2026 | 28/9/2026 | The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post. | |
| Aplazada | Alta (7.5) | 0.26% | — | Star-citizen EmbedvideoAI | 24/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute… | |
| Aplazada | Media (6.1) | 0.37% | — | Wpdeveloper EmbedpressAI | 18/9/2026 | 18/9/2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.5) | 0.49% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON… | |
| Aplazada | Alta (8.6) | 0.48% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to… | |
| Aplazada | Alta (7.5) | 0.49% | — | Star-citizen EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown… | |
| Aplazada | Media (5.3) | 0.27% | — | 3D Flipbook PDF EmbedderAI | 15/9/2026 | 17/9/2026 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full… | |
| Pendiente de análisis | Crítica (9.1) | 0.54% | — | Eclipse Embedded CDTAIARM Cmsis-packAI | 14/9/2026 | 16/9/2026 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk. | |
| Aplazada | Media (6.9) | 0.58% | — | Embedded-graphicsAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project… | |
| Aplazada | Media (6.9) | 0.52% | — | Embedded-graphicsAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through… | |
| Aplazada | Alta (8.8) | 0.51% | — | Youtube EmbedAI | 13/9/2026 | 14/9/2026 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will… | |
| Analizada | Crítica (9.8) | 7.5% | ⚠ Explotación activa | Checkpoint Gaia EmbeddedCheckpoint Gaia OS | 9/9/2026 | 23/9/2026 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | |
| Aplazada | Media (5.3) | 0.30% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows… | |
| Aplazada | Baja (2.7) | 0.28% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly… | |
| Aplazada | Baja (2.7) | 0.32% | — | Wpdeveloper EmbedpressAI | 5/9/2026 | 8/9/2026 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role. | |
| Aplazada | Crítica (10) | 0.55% | — | Embed Html5 GameAI | 2/9/2026 | 3/9/2026 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites. | |
| Aplazada | Media (5.3) | 0.19% | — | Bplugins Document EmbedderAI | 27/8/2026 | 28/8/2026 | The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs. | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Kaltura Html5libAIKaltura MwembedAI | 25/8/2026 | 3/9/2026 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the… | |
| Pendiente de análisis | Crítica (9.8) | 1.0% | — | Kaltura Html5libAIKaltura MwembedAI | 25/8/2026 | 3/9/2026 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s… | |
| Aplazada | Alta (7.1) | 0.25% | — | TagembedAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | |
| Aplazada | Media (6.4) | 0.55% | — | Lemmy-uiAIMarkdown-it-html5-embedAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a… | |
| Aplazada | Media (6.8) | 0.43% | — | Embed Google Photos AlbumAI | 14/8/2026 | 26/8/2026 | The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the… | |
| Aplazada | Media (6.5) | 0.29% | — | Davidartiss Code EmbedAI | 7/8/2026 | 9/9/2026 | The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper EmbedpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |