Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.23%—Colorbox Project Colorbox10/7/202614/7/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.
AnalizadaMedia (6.1)0.25%—Colorbox Project Colorbox23/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.
ModificadaAlta (8.8)0.25%—WP Gallery Metabox Project WP Gallery Metabox10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hardik Kalathiya WP Gallery Metabox plugin <= 1.0.0 versions.
ModificadaAlta (8.8)0.25%—Wp-flybox Project Wp-flybox3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cyle Conoly WP-FlyBox plugin <= 6.46 versions.
ModificadaMedia (4.3)0.46%—Gallery-metabox Project Gallery-metabox12/7/202317/6/2026
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post.
ModificadaMedia (4.3)0.41%—Gallery-metabox Project Gallery-metabox12/7/202317/6/2026
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
ModificadaAlta (8.8)0.27%—Gallery Metabox Project Gallery Metabox20/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions.
ModificadaMedia (4.8)0.44%—WP Login BOX Project WP Login BOX8/5/202317/6/2026
The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)4.9%—WP Live Chat Shoutbox Project WP Live Chat Shoutbox24/4/202317/6/2026
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
ModificadaMedia (6.1)0.46%—WP Live Chat Shoutbox Project WP Live Chat Shoutbox24/4/202317/6/2026
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.
ModificadaMedia (6.1)0.67%—Snippet BOX Project Snippet BOX11/4/202317/6/2026
Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field.
ModificadaMedia (5.4)0.47%—Easy Social BOX Project Easy Social BOX21/2/202317/6/2026
The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.5)1.0%—Octobox Project Octobox20/2/202317/6/2026
Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted search query string that will trigger a ReDoS vulnerability. This issue is fixed in PR 2807.
ModificadaAlta (8.8)0.72%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.
ModificadaCrítica (9.8)0.74%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php.
ModificadaAlta (7.5)0.75%—Jekbox Project Jekbox15/1/202317/6/2026
A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The patch is named…
ModificadaAlta (7.5)0.92%—V88 Smart TV BOX Project V88 Smart TV BOX FirmwareRK MAX Smart TV BOX Project RK MAX Smart TV BOX Firmware20/7/202217/6/2026
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
ModificadaAlta (7.5)1.1%—Toybox Project Toybox14/7/202217/6/2026
Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of Service (DoS) via unspecified vectors.
ModificadaCrítica (9.3)1.3%—Setupbox Project Setupbox11/7/202217/6/2026
The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (4.8)0.60%—Wp-appbox Project Wp-appbox11/4/202217/6/2026
Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20.
ModificadaCrítica (9.8)1.5%—JOX Project JOX30/3/202217/6/2026
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
ModificadaMedia (4.8)1.1%—Author BIO BOX Project Author BIO BOX15/10/202117/6/2026
The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in…
ModificadaAlta (8.1)0.77%—Abox Project Abox8/8/202117/6/2026
An issue was discovered in the abox crate before 0.4.1 for Rust. It implements Send and Sync for AtomicBox<T> with no requirement for T: Send and T: Sync.
ModificadaAlta (8.8)1.6%—Video-embed-box Project Video-embed-box7/6/202117/6/2026
The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.
ModificadaCrítica (9.8)1.6%—Cbox Project Cbox31/12/202017/6/2026
An issue was discovered in the cbox crate through 2020-03-19 for Rust. The CBox API allows dereferencing raw pointers without a requirement for unsafe code.