Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.27% | — | Friendsofflarum OauthAI | 25/9/2026 | 30/9/2026 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When… | |
| Aplazada | Alta (7.5) | 0.28% | — | Mikado-themes Pawfriends - PET Shop AND Veterinary Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3. | |
| Aplazada | Alta (8.1) | 0.34% | — | Mikado-themes PawfriendsAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows PHP Local File Inclusion.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a… | |
| Analizada | Media (6.9) | 0.50% | — | Friendsofshopware Froshadminer | 9/2/2026 | 17/6/2026 | FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users. This vulnerability… | |
| Aplazada | Media (5.4) | 0.12% | — | Mikado-themes Pawfriends - PET Shop AND Veterinary Wordpress ThemeAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.12% | — | TOP FriendsAI | 18/11/2025 | 17/6/2026 | The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing nonce validation on the top_friends_options_subpanel() function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted… | |
| Aplazada | Alta (8.7) | 1.3% | — | Apachefriends XamppAI | 30/8/2025 | 16/6/2026 | A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a… | |
| Analizada | Alta (8.8) | 0.76% | — | Alex.kirk Friends | 12/7/2025 | 17/6/2026 | The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable… | |
| Aplazada | Alta (7.1) | 0.37% | — | Pinal.shah Send-booking-invites-to-friendsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pinal.shah Send to a Friend Addon send-booking-invites-to-friends allows Reflected XSS.This issue affects Send to a Friend Addon: from n/a through <= 1.4.1. | |
| Aplazada | Media (5.3) | 0.44% | — | Alex.kirk FriendsAI | 6/12/2024 | 17/6/2026 | The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend… | |
| Aplazada | Alta (7.1) | 0.27% | — | Vietfriend Friendstore FOR WoocommerceAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VietFriend team FriendStore for WooCommerce friendstore-for-woocommerce allows Reflected XSS.This issue affects FriendStore for WooCommerce: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.5) | 0.44% | — | Apachefriends XamppAI | 17/5/2024 | 17/6/2026 | Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes. | |
| Analizada | Crítica (9.8) | 1.5% | — | Friendsofsymfony1 Symfony1 | 22/3/2024 | 17/6/2026 | Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget chain due to dangerous deserialization in `sfNamespacedParameterHolder` class that would enable an attacker to get remote code execution if… | |
| Analizada | Crítica (9) | 1.5% | — | Friendsofsymfony1 Symfony1 | 15/3/2024 | 17/6/2026 | Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 support. Symfony 1 has a gadget chain due to vulnerable Swift Mailer dependency that would enable an attacker to get remote code execution if a developer unserialize user input… | |
| Modificada | Media (5.5) | 0.46% | — | Alex.kirk Friends | 29/2/2024 | 17/6/2026 | The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating… | |
| Modificada | Crítica (9.8) | 0.46% | — | Apachefriends Xampp | 2/2/2024 | 17/6/2026 | A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH). | |
| Modificada | Media (6.7) | 0.26% | — | Apachefriends Xampp | 12/9/2023 | 17/6/2026 | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges. | |
| Modificada | Media (4.3) | 0.51% | — | Friendsofflarum Byobu | 1/8/2022 | 17/6/2026 | fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this has been patched. Users of Byobu with Flarum 1.0 or 1.1 should upgrade to Flarum 1.2 or later, or… | |
| Modificada | Alta (7.8) | 0.63% | — | Apachefriends Xampp | 9/6/2022 | 17/6/2026 | A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely. | |
| Modificada | Media (5.4) | 1.2% | — | Friendsofflarum Upload | 2/6/2022 | 17/6/2026 | FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary Javascript code decided by an attacker. This… | |
| Modificada | Alta (8.8) | 1.4% | — | Apachefriends Xampp | 23/5/2022 | 17/6/2026 | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Media (6.1) | 0.90% | — | Twitter Friends Widget Project Twitter Friends Widget | 9/9/2021 | 17/6/2026 | The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1. | |
| Modificada | Alta (8.8) | 22% | — | Apachefriends Xampp | 2/4/2020 | 17/6/2026 | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution. | |
| Modificada | Media (6.1) | 0.84% | — | Apachefriends Xampp | 9/7/2019 | 17/6/2026 | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569. | |
| Modificada | Media (6.1) | 5.7% | — | Apachefriends Xampp | 17/5/2019 | 17/6/2026 | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued. |