Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Holoborodko WP QuicklatexAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | |
| Aplazada | Alta (7.5) | 0.61% | — | Globo ThumborAI | 31/7/2026 | 8/9/2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0. | |
| Aplazada | Alta (7.5) | 0.75% | — | Globo.com ThumborAI | 31/7/2026 | 8/9/2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for % and /) without validating… | |
| Aplazada | Alta (8.7) | 0.52% | — | Globo.com ThumborAI | 31/7/2026 | 8/9/2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or frame filter input. This issue is fixed in 7.8.0. | |
| Aplazada | Alta (8.2) | 0.35% | — | Globo.com ThumborAI | 31/7/2026 | 8/9/2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can insert the same… | |
| Aplazada | Alta (8.2) | 0.50% | — | Globo ThumborAI | 31/7/2026 | 8/9/2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0. | |
| Aplazada | Media (4.3) | 0.18% | — | Lobot Slider AdministratorAI | 21/3/2026 | 17/6/2026 | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fourty_slider_options_page function. This makes it possible for unauthenticated attackers to modify plugin slider-page… | |
| Aplazada | Alta (8.5) | 0.29% | — | Vankarwai LoboAI | 8/1/2026 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.This issue affects Lobo: from n/a through < 2.8.6. | |
| Aplazada | Baja (2.1) | 0.26% | — | Samunatsu HalobotAI | 15/12/2025 | 17/6/2026 | A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to dynamically-managed code resources. The… | |
| Aplazada | Media (4.3) | 0.29% | — | Vankarwai LoboAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in VanKarWai Lobo lobo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lobo: from n/a through <= 2.8.6. | |
| Analizada | Alta (7.3) | 0.36% | — | Te-st Teplobot | 22/10/2024 | 17/6/2026 | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a… | |
| Modificada | Media (4.8) | 0.35% | — | Holoborodko WP Quicklatex | 22/7/2024 | 17/6/2026 | The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (7.1) | 0.43% | — | Holoborodko WP Quicklatex | 13/7/2024 | 17/6/2026 | The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (7.8) | 1.2% | — | Loboevolution Project Loboevolution | 26/6/2018 | 17/6/2026 | LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via… |