Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.37% | — | Maian SearchAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. | |
| Aplazada | Alta (8.1) | 0.75% | — | Maian SearchAIFrankenphpAI | 10/6/2026 | 17/6/2026 | FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into… | |
| Aplazada | Media (5.1) | 0.17% | — | Maian Support HelpdeskAI | 3/2/2026 | 17/6/2026 | Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system. | |
| Aplazada | Alta (8.1) | 0.73% | — | Thembay MaiaAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Maia maia allows PHP Local File Inclusion.This issue affects Maia: from n/a through <= 1.1.15. | |
| Modificada | Media (4.8) | 0.51% | — | Maianmedia Maianaffiliate | 16/6/2022 | 17/6/2026 | A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel. | |
| Modificada | Media (5.4) | 0.74% | — | Maianmedia Maianaffiliate | 16/6/2022 | 17/6/2026 | A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel. | |
| Modificada | Crítica (9.8) | 66% | — | Maianscriptworld Maian Cart | 7/10/2021 | 17/6/2026 | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | |
| Modificada | Media (4.8) | 0.52% | — | Maianaffiliate | 22/9/2021 | 17/6/2026 | MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database. | |
| Modificada | Alta (7.2) | 1.3% | — | Maianmedia Maianaffiliate | 20/9/2021 | 17/6/2026 | MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors. | |
| Modificada | Media (4.3) | 1.2% | — | Maianscriptworld Maian Weblog | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) subject parameter in a contact action to index.php. | |
| Modificada | Media (6.8) | 0.61% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php. | |
| Modificada | Media (5) | 1.8% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 2.1% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Maian Script World Maian Uploader | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php. | |
| Modificada | Alta (10) | 1.2% | — | Maian GalleryMenalto Gallery | 22/4/2012 | 16/6/2026 | Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113. | |
| Modificada | Media (4.3) | 1.7% | — | Maian GalleryMenalto Gallery | 22/4/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Aretimes COM Maianmedia | 16/2/2011 | 16/6/2026 | SQL injection vulnerability in the Maian Media Silver (com_maianmedia) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a music action to index.php. | |
| Modificada | Alta (7.5) | 6.6% | — | Maianscriptworld Maian Greetings | 26/8/2009 | 16/6/2026 | Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin. | |
| Modificada | Alta (7.5) | 7.8% | — | Maian Links | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie. | |
| Modificada | Alta (7.5) | 6.5% | — | Maian Guestbook | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie. | |
| Modificada | Alta (7.5) | 6.6% | — | Maian Recipe | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie. | |
| Modificada | Alta (7.5) | 8.0% | — | Maian Script World Maian Search | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie. | |
| Modificada | Alta (7.5) | 8.1% | — | Maian Weblog | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie. | |
| Modificada | Alta (7.5) | 7.8% | — | Maian Script World Maian Uploader | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Music | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search action to index.php, and the (2) msg_script parameter to admin/inc/footer.php. |