Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7)0.14%—LektorAI1/10/20262/10/2026
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can…
Pendiente de análisisMedia (6.9)0.52%—Linuxfoundation Inspektor GadgetAI15/9/202630/9/2026
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a…
Pendiente de análisisBaja (2.9)0.63%—Linuxfoundation Inspektor GadgetAI15/9/202630/9/2026
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to crash or exhaust the memory of the privileged Inspektor Gadget…
AplazadaAlta (7.5)0.63%—LektorAI28/8/20261/9/2026
A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive information such…
AplazadaAlta (7.3)0.16%—RedisAIContribsys FaktoryAI25/8/20269/9/2026
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup configuration to a fixed, predictable,…
AplazadaAlta (8.7)0.45%—Contribsys FaktoryAI25/8/20269/9/2026
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and several command handlers slice or index the received line at a fixed…
Pendiente de análisisMedia (5.9)0.37%—Jetbrains KtorAI17/8/202628/8/2026
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
AplazadaMedia (6.5)0.22%—Vektor-inc VK ALL IN ONE Expansion UnitAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3.
AnalizadaMedia (4.8)0.15%—Linuxfoundation Inspektor Gadget12/3/202617/6/2026
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will silently drop events. The…
AplazadaMedia (6.4)0.20%—Vektor-inc VK ALL IN ONE Expansion UnitAI18/2/202617/6/2026
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns_title' parameter in all versions up to, and including, 9.112.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AnalizadaMedia (6.9)0.73%—Linuxfoundation Inspektor Gadget12/2/202617/6/2026
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are rendered to the terminal without any sanitization of control characters or ANSI escape sequences. Therefore, a…
ModificadaMedia (6.3)0.27%—Farktor E-commerce Package12/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating User-Controlled Variables. This issue affects E-Commerce Package: through 27112025.
ModificadaMedia (6.1)0.23%—Farktor E-commerce Package12/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS). This issue affects E-Commerce Package: through 27112025.
ModificadaCrítica (9.8)0.37%—Farktor E-commerce Package12/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection. This issue affects E-Commerce Package: through 27112025.
ModificadaMedia (6.6)1.4%—Linuxfoundation Inspektor Gadget29/1/202617/6/2026
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is implemented in the file…
AplazadaMedia (6.5)0.16%—Vektor VK Google JOB Posting ManagerAI16/12/202530/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Stored XSS.This issue affects VK Google Job Posting Manager: from n/a through <= 1.2.22.
AplazadaMedia (6.4)0.23%—Vektor-inc VK ALL IN ONE Expansion UnitAI18/11/202517/6/2026
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, and including, 9.112.1. This is due to insufficient input sanitization and output escaping on the user-supplied Custom CSS value. This makes it possible for…
AplazadaMedia (6.4)0.23%—Vektor-inc VK ALL IN ONE Expansion UnitAI18/11/202517/6/2026
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions up to, and including, 9.112.1. This is due to a logic error in the CTA save function that reads sanitization callbacks from the wrong…
AplazadaMedia (4.3)0.24%—Faktor Vier F4 Media TaxonomiesAI3/9/202517/6/2026
Missing Authorization vulnerability in FAKTOR VIER F4 Media Taxonomies f4-media-taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects F4 Media Taxonomies: from n/a through <= 1.1.4.
AplazadaAlta (7.2)0.46%—Risk Yazilim Teknolojileri Reel Sektor Hazine VE Risk Yonetimi YazilimiAI15/8/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection. This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılımı: through 1.0.0.4.
AplazadaMedia (6.5)0.39%—Vektor-inc VK Filter SearchAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Filter Search vk-filter-search allows Stored XSS.This issue affects VK Filter Search: from n/a through <= 2.20.2.
AnalizadaMedia (5.3)0.32%—Jetbrains Ktor12/3/202517/6/2026
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
AplazadaMedia (4.3)0.33%—Vektor-inc VK BlocksAI7/3/202517/6/2026
The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private posts and…
AplazadaAlta (7.1)0.26%—Faktor Vier F4 Post TreeAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Post Tree f4-tree allows Reflected XSS.This issue affects F4 Post Tree: from n/a through <= 1.1.18.
AnalizadaMedia (4.8)0.30%—Vektor-inc VK ALL IN ONE Expansion Unit13/11/202417/6/2026
Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing the web site using the product.