Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.78% | — | OpeneqellaAIApache FreemarkerAI | 20/9/2026 | 24/9/2026 | openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService… | |
| Analizada | Crítica (9.1) | 0.85% | — | Apache Freemarker | 10/9/2026 | 11/9/2026 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users… | |
| Aplazada | Alta (8.8) | 1.1% | — | MarkerAITiangolo FastapiAI | 4/9/2026 | 23/9/2026 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Maps Marker PROAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | |
| Aplazada | Baja (2) | 0.41% | — | Apache FreemarkerAIPubliccmsAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker Template Handler. Such manipulation… | |
| Aplazada | Crítica (9.9) | 1.0% | — | Running-elephant DatartAIApache FreemarkerAI | 17/2/2026 | 17/6/2026 | A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field. | |
| Aplazada | Media (5.3) | 0.27% | — | Krishaweb ADD Multiple MarkerAI | 11/11/2025 | 30/9/2026 | The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to update the map… | |
| Aplazada | Media (5.5) | 0.43% | — | Kingdee Cloud-starry-sky Enterprise EditionAIApache FreemarkerAI | 27/6/2025 | 17/6/2026 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of the file \k3\o2o\bos\webapp\action\DynamicForm 4 Action.class of the component Freemarker Engine. The manipulation leads to… | |
| Aplazada | Alta (8.5) | 0.33% | — | Davidfcarr RsvpmarkerAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.5.6. | |
| Analizada | Media (5.3) | 0.47% | — | Rems Road Accident MAP Marker | 29/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Affected by this issue is some unknown functionality of the file /endpoint/add-mark.php. The manipulation of the argument mark_name/details leads to cross site scripting. The attack may be launched… | |
| Analizada | Media (5.3) | 0.52% | — | Rems Interactive MAP With Marker | 25/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.26% | — | Mapsmarker Leaflet Maps Marker | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MapsMarker.Com e.U. Leaflet Maps Marker allows Stored XSS.This issue affects Leaflet Maps Marker: from n/a through 3.12.9. | |
| Analizada | Media (5.3) | 0.46% | — | Rems Interactive MAP With Marker | 16/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Marker Name of the component Add Marker. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.61% | — | Rems Interactive MAP With Marker | 16/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (6.4) | 0.43% | — | Mapsmarker Leaflet Maps MarkerAI | 2/5/2024 | 17/6/2026 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mapsmarker' shortcode in all versions up to, and including, 3.12.8 due to insufficient input sanitization and output escaping on user supplied attributes such as… | |
| Aplazada | Media (4.3) | 0.20% | — | Marker.ioAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marker.Io Marker.Io.This issue affects Marker.Io : from n/a through 1.1.8. | |
| Analizada | Media (6.1) | 0.65% | — | Markerhub Eblog | 21/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script to the argument description parameter when submitting a comment on a post. | |
| Modificada | Crítica (9.8) | 1.5% | — | Github Cmark-gfmGjtorikian Commonmarker | 4/1/2024 | 14/7/2026 | CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more… | |
| Modificada | Alta (8.8) | 0.26% | — | Krishaweb ADD Multiple Marker | 23/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions. | |
| Modificada | Media (6.1) | 0.41% | — | MAP Multi Marker Project MAP Multi Marker | 20/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Mickael Austoni Map Multi Marker plugin <= 3.2.1 versions. | |
| Modificada | Media (5.4) | 0.56% | — | Mapsmarker Leaflet Maps Marker | 6/2/2023 | 17/6/2026 | The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Alta (7.2) | 1.3% | — | Mapsmarker Leaflet Maps Marker | 29/8/2022 | 17/6/2026 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks. | |
| Modificada | Crítica (9.6) | 28% | — | Wavemaker Wavemarker Studio | 21/2/2019 | 17/6/2026 | com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF. | |
| Modificada | Media (4.3) | 2.0% | — | Dmca Watermarker | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in phprack.php in the DMCA WaterMarker plugin before 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the plugin_dir parameter. | |
| Modificada | Media (4.3) | 3.8% | — | Mapsmarker Leaflet Maps Marker Plugin | 21/5/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php. |