Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.22% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store… | |
| Aplazada | Media (6.8) | 0.29% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for… | |
| Aplazada | Media (6.4) | 0.19% | — | Real3d Flipbook LiteAI | 19/9/2026 | 21/9/2026 | The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) in versions up to, and including, 5.1.1. This is due to insufficient input sanitization and output escaping in the… | |
| Aplazada | Media (5.3) | 0.27% | — | 3D Flipbook PDF EmbedderAI | 15/9/2026 | 17/9/2026 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full… | |
| Aplazada | Media (6.4) | 0.36% | — | Dear FlipbookAI | 5/9/2026 | 8/9/2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.4) | 0.35% | — | Dear FlipbookAI | 5/9/2026 | 8/9/2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Crítica (9.3) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 27/8/2026 | 28/8/2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to… | |
| Aplazada | Media (6) | 0.24% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and… | |
| Aplazada | Alta (8.5) | 0.23% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect… | |
| Aplazada | Alta (8.7) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames and exfiltrate stored photos and videos.… | |
| Aplazada | Crítica (9.4) | 0.09% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 21/8/2026 | 26/8/2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE,… | |
| Aplazada | Media (5.3) | 0.33% | — | 3dflipbook 3D FlipbookAI | 18/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | |
| Aplazada | Media (4.3) | 0.29% | — | Flippercode WP MapsAI | 31/7/2026 | 12/8/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6. | |
| Aplazada | Alta (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Analizada | Alta (7.1) | 0.45% | — | Pulseextensions Flip Wall | 19/6/2026 | 19/8/2026 | Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid parameter containing SQL… | |
| Aplazada | Media (5.3) | 0.25% | — | Avirtum Ipages FlipbookAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1. | |
| Aplazada | Media (6.4) | 0.32% | — | Epaperflip PublisherAI | 9/6/2026 | 23/7/2026 | The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed` shortcode in all versions up to, and including, 1. This is due to insufficient input sanitization and output escaping on the shortcode attribute which is injected… | |
| Aplazada | Media (4.3) | 0.27% | — | Dearhive DearflipAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27. | |
| Aplazada | Alta (8.4) | 0.19% | — | Flipper Devices Flipperzero FirmwareAI | 1/5/2026 | 17/6/2026 | flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function. | |
| Aplazada | Media (6.4) | 0.33% | — | Flipbox Addon FOR ElementorAI | 18/4/2026 | 17/6/2026 | The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2.1.1 due to insufficient validation of custom attribute names. Specifically, the plugin uses `esc_html()` on the… | |
| Aplazada | Media (5.3) | 0.89% | — | 3D Flipbook PDF EmbedderAI | 15/4/2026 | 17/6/2026 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.30% | — | Ckthemes FlipmartAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flipmart: from n/a through <= 2.8. | |
| Aplazada | Alta (7.5) | 0.70% | — | Flippercode WP MapsAI | 11/3/2026 | 17/6/2026 | The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in backticks as column names,… | |
| Aplazada | Media (6.4) | 0.26% | — | Dear FlipbookAI | 11/3/2026 | 17/6/2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PDF page labels in all versions up to, and including, 2.4.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (3.8) | 0.24% | — | Creativeinteractivemedia Real 3D FlipbookAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1. |