Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.5) | — | — | Siteorigin Widgets BundleAI | 2/10/2026 | 2/10/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the… | |
| Aplazada | Alta (7.2) | 0.54% | — | Siteorigin Page BuilderAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.32% | — | Oracle Banking OriginationAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Originlab Origin ViewerAI | 15/9/2026 | 16/9/2026 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Originlab Origin ViewerAI | 15/9/2026 | 16/9/2026 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.1) | 0.28% | — | Ipgp Visitors OriginAI | 5/9/2026 | 8/9/2026 | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request. | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab Origin ViewerAI | 20/8/2026 | 31/8/2026 | OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab Origin ViewerAI | 20/8/2026 | 31/8/2026 | OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab OriginproAI | 20/8/2026 | 2/9/2026 | OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab OriginproAI | 20/8/2026 | 2/9/2026 | OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab OriginproAI | 20/8/2026 | 2/9/2026 | OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab OriginproAI | 20/8/2026 | 2/9/2026 | OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab OriginproAI | 20/8/2026 | 2/9/2026 | OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Banking Origination | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration). The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.… | |
| Aplazada | Media (6.4) | 0.42% | — | Siteorigin Page BuilderAI | 27/6/2026 | 29/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.4) | 0.30% | — | Livemesh Siteorigin WidgetsAI | 27/5/2026 | 17/6/2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user… | |
| Aplazada | Alta (8.8) | 0.92% | — | Siteorigin Page BuilderAI | 3/3/2026 | 17/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server,… | |
| Aplazada | Alta (7.7) | 0.46% | — | Fiserv Originate Loans PeripheralsAI | 23/2/2026 | 17/6/2026 | The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) in unsupported version 2021.2.4 (build 4.7.3155.0011) uses deprecated .NET Remoting TCP channels that allow unsafe deserialization of untrusted data. When these services are exposed to an untrusted network in a… | |
| Aplazada | Media (5.4) | 0.29% | — | Siteorigin Widgets BundleAI | 18/2/2026 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all versions up to, and including, 1.70.4. This is due to a missing capability check on the `siteorigin_widget_preview_widget_action()` function which is registered via the `wp_ajax_so_widgets_preview`… | |
| Aplazada | Media (6.4) | 0.22% | — | Livemesh Siteorigin WidgetsAI | 13/12/2025 | 30/9/2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.24% | — | Originality AI AI CheckerAI | 24/10/2025 | 17/6/2026 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ai_scan_result_remove' function in all versions up to, and including, 1.0.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all… | |
| Aplazada | Media (4.3) | 0.21% | — | Originality AI AI CheckerAI | 24/10/2025 | 17/6/2026 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ai_get_table' function in all versions up to, and including, 1.0.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read all data in… | |
| Aplazada | Media (5.4) | 0.33% | — | GO Http.crossoriginprotectionAI | 22/9/2025 | 17/6/2026 | When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections. | |
| Aplazada | Media (6.5) | 0.21% | — | Origincode Video Gallery - Vimeo AND Youtube GalleryAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in origincode Video Gallery – Vimeo and YouTube Gallery smart-grid-gallery allows Stored XSS.This issue affects Video Gallery – Vimeo and YouTube Gallery: from n/a through <= 1.1.7. | |
| Analizada | Media (5.4) | 0.19% | — | Siteorigin Widgets Bundle | 25/6/2025 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… |