Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.40%—Ancorathemes MelodyAI25/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue affects Melody: from n/a through <= 1.6.3.
AnalizadaAlta (8.6)0.59%—Phpsugar PHP Melody1/2/202617/6/2026
PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter to execute arbitrary database queries and potentially compromise the web application and database…
AnalizadaMedia (5.1)0.35%—Phpsugar PHP Melody1/2/202617/6/2026
PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent…
AnalizadaMedia (5.1)0.26%—Phpsugar PHP Melody1/2/202617/6/2026
PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.
AnalizadaMedia (5.1)0.26%—Phpsugar PHP Melody1/2/202617/6/2026
PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.
ModificadaCrítica (9.8)28%—Javamelody Project Javamelody26/9/201817/6/2026
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
ModificadaMedia (6.1)0.71%—Javamelody Project Javamelody14/6/201817/6/2026
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
ModificadaCrítica (9.8)1.9%—Phpsugar PHP Melody9/1/201817/6/2026
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
ModificadaCrítica (9.8)2.4%—Phpsugar PHP Melody24/10/201717/6/2026
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
ModificadaMedia (6.1)0.66%—Phpsugar PHP Melody19/10/201717/6/2026
In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.
ModificadaCrítica (9.8)1.5%—Phpsugar PHP Melody18/10/201717/6/2026
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
ModificadaAlta (8.8)1.3%—Phpsugar PHP Melody18/10/201717/6/2026
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
ModificadaMedia (4.3)2.8%—Emeric Vernat Javamelody30/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.