Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.40% | — | MilkdownAIMilkdown Plugin EmojiAI | 24/7/2026 | 27/7/2026 | Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs handler stores raw… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdo RemojiAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDO Remoji remoji allows Stored XSS.This issue affects Remoji: from n/a through <= 2.2. | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex EmojinationAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX EmojiNation emojination allows PHP Local File Inclusion.This issue affects EmojiNation: from n/a through <= 1.0.12. | |
| Aplazada | Alta (8.6) | 0.75% | — | Nodebb Plugin EmojiAI | 21/1/2026 | 17/6/2026 | NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file… | |
| Modificada | Media (5.4) | 0.24% | — | Elsner Emoji Shortcode | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Emoji Shortcode emoji-shortcode allows Stored XSS.This issue affects Emoji Shortcode: from n/a through <= 1.0.0. | |
| Modificada | Alta (8.8) | 0.27% | — | Monchito WP Emoji ONE | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Monchito.Net WP Emoji One plugin <= 0.6.0 versions. | |
| Modificada | Media (5.5) | 0.19% | — | Ekatox Facemoji\ | 9/6/2023 | 17/6/2026 | An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the SharedPreference files. | |
| Modificada | Alta (7.8) | 0.38% | — | Ekatox Facemoji Emoji Keyboard | 9/6/2023 | 17/6/2026 | An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component. | |
| Modificada | Alta (7.8) | 0.95% | — | Wavekeyboard Wave Animated Keyboard Emoji | 30/5/2023 | 17/6/2026 | An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files. | |
| Modificada | Media (5.5) | 0.34% | — | Wavekeyboard Wave Animated Keyboard Emoji | 30/5/2023 | 17/6/2026 | An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files. | |
| Modificada | Alta (7.5) | 1.2% | — | Denosaurs Emoji | 28/4/2023 | 17/6/2026 | The Denosaurs emoji package provides emojis for dinosaurs. Starting in version 0.1.0 and prior to version 0.3.0, the reTrimSpace regex has 2nd degree polynomial inefficiency, leading to a delayed response given a big payload. The issue has been patched in 0.3.0. As a workaround, avoid using the `replace`, `unemojify`,… | |
| Modificada | Media (6.1) | 1.0% | — | Emoji Button Project Emoji Button | 26/11/2021 | 17/6/2026 | @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code. | |
| Modificada | Alta (7.8) | 0.25% | — | Samsung AR Emoji Editor | 8/7/2021 | 17/6/2026 | Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated privilege. | |
| Modificada | Media (5.4) | 0.27% | — | Swiftkey Keyboard + Emoji | 9/9/2014 | 17/6/2026 | The SwiftKey Keyboard + Emoji (aka com.touchtype.swiftkey) application 5.0.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |