Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.43% | — | Felixriddle Dev-jobs-handlebarsAI | 16/10/2025 | 17/6/2026 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point… | |
| Rechazada | Sin puntuar | — | — | Apache FelixAI | 3/10/2025 | 3/10/2025 | Rejected reason: Further research determined the issue is not an independent vulnerability as it originates from Apache Felix. | |
| Aplazada | Alta (7.1) | 0.13% | — | Devfelixmoira Knowledge Base MakerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8. | |
| Aplazada | Media (5.9) | 0.26% | — | Felix Martinez Recipes Manager - WPHAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Félix Martínez Recipes manager - WPH allows Stored XSS. This issue affects Recipes manager - WPH: from n/a through 1.0.4. | |
| Aplazada | Alta (7.1) | 0.15% | — | Felixtz Modern-pollsAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in felixtz Modern Polls modern-polls allows Stored XSS.This issue affects Modern Polls: from n/a through <= 1.0.10. | |
| Analizada | Media (6.3) | 0.16% | — | Felixker Wordpress/plugin Upgrade Time OUT Plugin | 9/4/2025 | 17/6/2026 | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Media (5.6) | 0.56% | — | Apache Felix Http Webconsole Plugin | 12/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue. | |
| Analizada | Media (6.1) | 0.69% | — | Apache Felix Webconsole | 10/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue. | |
| Aplazada | Media (6.5) | 0.41% | — | Devfelixmoira Poll BuilderAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devfelixmoira Poll Builder poll-builder allows Stored XSS.This issue affects Poll Builder: from n/a through <= 1.3.5. | |
| Aplazada | Media (5.4) | 0.34% | — | Felixwelberg Extended Post StatusAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19. | |
| Analizada | Media (5.3) | 0.22% | — | Devfelixmoira Limit Login Attempts Plus | 19/9/2024 | 17/6/2026 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header… | |
| Aplazada | Media (6.5) | 0.25% | — | Felixmoira Popup More PopupsAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira Popup More Popups allows Stored XSS.This issue affects Popup More Popups: from n/a through 2.3.1. | |
| Analizada | Media (5.4) | 0.62% | — | Felixschwarz Mjml-python | 22/2/2024 | 17/6/2026 | The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users of `FelixSchwarz/mjml-python` who insert untrusted data into mjml templates unless that data is checked in a very strict manner. User input like… | |
| Analizada | Alta (7.2) | 0.66% | — | Felixmoira AI Popup | 2/2/2024 | 17/6/2026 | The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files ending… | |
| Modificada | Crítica (9.8) | 0.68% | — | Felixwelberg SIS Handball | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Felix Welberg SIS Handball allows SQL Injection.This issue affects SIS Handball: from n/a through 1.0.45. | |
| Modificada | Alta (8.8) | 0.24% | — | Felixwelberg SIS Handball | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Felix Welberg SIS Handball plugin <= 1.0.45 versions. | |
| Modificada | Media (6.1) | 2.2% | — | Apache Felix Health Check Webconsole Plugin | 25/7/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin… | |
| Modificada | Media (4.6) | 0.39% | — | Tedfelix Acpid2 | 29/8/2012 | 16/6/2026 | event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls. | |
| Modificada | Media (4.4) | 0.61% | — | Tedfelix Acpid2 | 29/8/2012 | 16/6/2026 | samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands. | |
| Modificada | Baja (2.1) | 1.1% | — | Tedfelix Acpid | 5/10/2011 | 16/6/2026 | acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls. | |
| Modificada | Media (5) | 1.3% | — | Xavier Ducrohet Felix | 9/1/2001 | 16/6/2026 | Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. |