Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.23% | — | Colorbox Project Colorbox | 10/7/2026 | 14/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0. | |
| Analizada | Media (6.1) | 0.25% | — | Colorbox Project Colorbox | 23/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3. | |
| Modificada | Alta (8.8) | 0.25% | — | WP Gallery Metabox Project WP Gallery Metabox | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hardik Kalathiya WP Gallery Metabox plugin <= 1.0.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wp-flybox Project Wp-flybox | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cyle Conoly WP-FlyBox plugin <= 6.46 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Gallery-metabox Project Gallery-metabox | 12/7/2023 | 17/6/2026 | The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post. | |
| Modificada | Media (4.3) | 0.41% | — | Gallery-metabox Project Gallery-metabox | 12/7/2023 | 17/6/2026 | The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin. | |
| Modificada | Alta (8.8) | 0.27% | — | Gallery Metabox Project Gallery Metabox | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions. | |
| Modificada | Media (4.8) | 0.44% | — | WP Login BOX Project WP Login BOX | 8/5/2023 | 17/6/2026 | The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 4.9% | — | WP Live Chat Shoutbox Project WP Live Chat Shoutbox | 24/4/2023 | 17/6/2026 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Media (6.1) | 0.46% | — | WP Live Chat Shoutbox Project WP Live Chat Shoutbox | 24/4/2023 | 17/6/2026 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Modificada | Media (6.1) | 0.67% | — | Snippet BOX Project Snippet BOX | 11/4/2023 | 17/6/2026 | Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field. | |
| Modificada | Media (5.4) | 0.47% | — | Easy Social BOX Project Easy Social BOX | 21/2/2023 | 17/6/2026 | The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.5) | 1.0% | — | Octobox Project Octobox | 20/2/2023 | 17/6/2026 | Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted search query string that will trigger a ReDoS vulnerability. This issue is fixed in PR 2807. | |
| Modificada | Alta (8.8) | 0.72% | — | Forget Heart Message BOX Project Forget Heart Message BOX | 1/2/2023 | 17/6/2026 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php. | |
| Modificada | Crítica (9.8) | 0.74% | — | Forget Heart Message BOX Project Forget Heart Message BOX | 1/2/2023 | 17/6/2026 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php. | |
| Modificada | Alta (7.5) | 0.75% | — | Jekbox Project Jekbox | 15/1/2023 | 17/6/2026 | A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The patch is named… | |
| Modificada | Alta (7.5) | 0.92% | — | V88 Smart TV BOX Project V88 Smart TV BOX FirmwareRK MAX Smart TV BOX Project RK MAX Smart TV BOX Firmware | 20/7/2022 | 17/6/2026 | An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service. | |
| Modificada | Alta (7.5) | 1.1% | — | Toybox Project Toybox | 14/7/2022 | 17/6/2026 | Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of Service (DoS) via unspecified vectors. | |
| Modificada | Crítica (9.3) | 1.3% | — | Setupbox Project Setupbox | 11/7/2022 | 17/6/2026 | The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.8) | 0.60% | — | Wp-appbox Project Wp-appbox | 11/4/2022 | 17/6/2026 | Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20. | |
| Modificada | Crítica (9.8) | 1.5% | — | JOX Project JOX | 30/3/2022 | 17/6/2026 | An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput. | |
| Modificada | Media (4.8) | 1.1% | — | Author BIO BOX Project Author BIO BOX | 15/10/2021 | 17/6/2026 | The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in… | |
| Modificada | Alta (8.1) | 0.77% | — | Abox Project Abox | 8/8/2021 | 17/6/2026 | An issue was discovered in the abox crate before 0.4.1 for Rust. It implements Send and Sync for AtomicBox<T> with no requirement for T: Send and T: Sync. | |
| Modificada | Alta (8.8) | 1.6% | — | Video-embed-box Project Video-embed-box | 7/6/2021 | 17/6/2026 | The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection. | |
| Modificada | Crítica (9.8) | 1.6% | — | Cbox Project Cbox | 31/12/2020 | 17/6/2026 | An issue was discovered in the cbox crate through 2020-03-19 for Rust. The CBox API allows dereferencing raw pointers without a requirement for unsafe code. |