Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Vercel FlagsAIVercel FlagsAI | 2/5/2025 | 17/6/2026 | Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags from 3.1.1 and prior as certain circumstances allows a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags discovery endpoint… | |
| Aplazada | Alta (7.1) | 0.21% | — | Ab-tools Flags WidgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ab-tools Flags Widget flags-widget allows Stored XSS.This issue affects Flags Widget: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.9) | 0.26% | — | Vasilis Triantafyllou Flag IconsAIVasilis Triantafyllou Language-icons-flags-switcherAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vasilis Triantafyllou Flag Icons language-icons-flags-switcher allows Stored XSS.This issue affects Flag Icons: from n/a through <= 2.2. | |
| Analizada | Alta (7.5) | 0.40% | — | Flagsmith | 17/11/2024 | 17/6/2026 | In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions. | |
| Analizada | Alta (7.5) | 0.42% | — | Flagsmith | 17/11/2024 | 17/6/2026 | In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting. | |
| Aplazada | Media (6.5) | 0.25% | — | Wepic Country Flags FOR ElementorAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wepic Country Flags for Elementor allows Stored XSS.This issue affects Country Flags for Elementor: from n/a through 1.0.1. | |
| Modificada | Media (4.3) | 0.48% | — | Language BAR Flags Project Language BAR Flags | 13/9/2021 | 17/6/2026 | The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which… | |
| Modificada | Media (5) | 9.8% | — | Flagship Industries Ventrilo | 14/8/2008 | 16/6/2026 | The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784. | |
| Modificada | Media (5) | 7.8% | — | Flagship Industries Ventrilo | 30/8/2005 | 16/6/2026 | Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784. | |
| Modificada | Media (6.2) | 0.75% | — | Multisoft Flagship | 20/10/2000 | 16/6/2026 | The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses. |