Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Lingotek RAY Enterprise TranslationAI | 11/8/2026 | 26/8/2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages. | |
| Aplazada | Media (6.5) | 0.30% | — | Lingotek RAY Enterprise TranslationAI | 11/8/2026 | 26/8/2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value. | |
| Analizada | Media (4.3) | 0.14% | — | Lingotek RAY Enterprise Translation | 10/7/2026 | 7/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4. | |
| Aplazada | Alta (7.5) | 0.43% | — | Lingotek RAY Enterprise TranslationAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows PHP Local File Inclusion.This issue affects Ray Enterprise Translation: from n/a through <= 1.7.1. | |
| Aplazada | Alta (7.2) | 0.48% | — | Official Integration FOR BillingoAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation.This issue affects Official Integration for Billingo: from n/a through <= 4.3.0. | |
| Aplazada | Media (5.4) | 0.27% | — | Lingotek-translationAILingotek RAY Enterprise TranslationAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ray Enterprise Translation: from n/a through <= 1.7.2. | |
| Aplazada | Alta (7.5) | 0.55% | — | BelingogeoAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo belingogeo allows Path Traversal.This issue affects belingoGeo: from n/a through <= 1.12.0. | |
| Aplazada | Alta (7.5) | 0.70% | — | Lingotek RAY Enterprise TranslationAI | 17/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows PHP Local File Inclusion.This issue affects Ray Enterprise Translation: from n/a through <= 1.7.0. | |
| Aplazada | Media (6.5) | 0.40% | — | Mark Winiarski WplingoAI | 14/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLingo: from n/a through <= 1.1.2. | |
| Modificada | Media (4.8) | 0.50% | — | Official Integration FOR Billingo Project Official Integration FOR Billingo | 31/10/2022 | 17/6/2026 | The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.1) | 0.37% | — | WOO Billingo Plus Project WOO Billingo PlusIntegration FOR Billingo & Gravity Forms Project Integration FOR Billingo & Gravity FormsIntegration FOR Szamlazz.hu & Gravity Forms Project Integration FOR Szamlazz.hu & Gravity Forms | 10/10/2022 | 17/6/2026 | The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above… | |
| Modificada | Alta (7.5) | 2.8% | — | Apache Olingo | 9/1/2020 | 17/6/2026 | Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call… | |
| Modificada | Alta (7.5) | 2.1% | — | Apache Olingo | 4/12/2019 | 17/6/2026 | The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the header, then it can help to implement a DoS attack. | |
| Modificada | Crítica (9.8) | 3.6% | — | Apache Olingo | 4/12/2019 | 17/6/2026 | Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case. | |
| Modificada | Media (5.5) | 12% | — | Apache Olingo | 4/12/2019 | 17/6/2026 | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks. | |
| Modificada | Crítica (9.8) | 1.4% | — | Flashlingo Project Flashlingo | 26/8/2019 | 17/6/2026 | FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js. | |
| Modificada | Alta (8.1) | 3.5% | — | Duolingo Tinycards | 5/1/2018 | 17/6/2026 | The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and consequently achieve remote code execution, via a man-in-the-middle attack. | |
| Modificada | Media (5.4) | 0.27% | — | Chillingo Flying FOX | 21/10/2014 | 17/6/2026 | The Flying Fox (aka com.chillingo.slyfoxfree.android.aja) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Slingo Lottery Challenge | 9/9/2014 | 17/6/2026 | The Slingo Lottery Challenge (aka com.slingo.slingolotterychallenge) application 1.0.34 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 1.1% | — | Lingotek | 6/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Lingotek module 6.x-1.x before 6.x-1.40 for Drupal allow remote authenticated users to inject arbitrary web script or HTML when (1) creating or (2) editing page content. | |
| Modificada | Media (6.9) | 0.36% | — | Lindo Lingo | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in LINGO 11.0.1.6 and 12.0.2.20 allows local users to gain privileges via a Trojan horse myuser.dll file in the current working directory, as demonstrated by a directory that contains a .ltf file. NOTE: the provenance of this information is unknown; the details are obtained solely… |