Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 15/9/2026 | A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used.… | |
| Aplazada | Baja (0.9) | 0.16% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 16/9/2026 | A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be… | |
| Aplazada | Alta (8.7) | 0.93% | — | Openwrt Luci-app-bmx7AI | 3/8/2026 | 9/9/2026 | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Popup BOXAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions. | |
| Aplazada | Media (5) | 0.11% | — | Gpac Project Mp4boxAI | 3/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.16% | — | Gpac Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (4.3) | 0.44% | — | Gpac Mp4boxAI | 27/5/2026 | 5/10/2026 | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV). | |
| Analizada | Media (5.4) | 0.14% | — | Ays-pro Popup BOX | 7/4/2026 | 30/9/2026 | The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups… | |
| Aplazada | Alta (8.8) | 0.49% | — | WP Life Modal Popup BOXAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1. | |
| Aplazada | Media (6.4) | 0.20% | — | Popup BOXAI | 18/2/2026 | 17/6/2026 | The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.19% | — | Popup BOXAI | 31/1/2026 | 17/6/2026 | The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in the request. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.12% | — | AYS Popup BOXAI | 30/12/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 6.0.7. | |
| Aplazada | Media (5.3) | 0.14% | — | AYS Systems AYS Popup BOXAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 5.5.4. | |
| Analizada | Media (5.4) | 0.33% | — | Ays-pro Popup BOX | 15/5/2025 | 17/6/2026 | The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.30% | — | Tchgdns Wp-appbox | 21/2/2025 | 17/6/2026 | The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.21% | — | Wow-company Popup BOXAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Popup Box popup-box allows Cross Site Request Forgery.This issue affects Popup Box: from n/a through <= 3.2.4. | |
| Aplazada | Alta (7.8) | 0.25% | — | Gpac Mp4boxAI | 24/1/2025 | 17/6/2026 | GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns | |
| Aplazada | Media (6.1) | 0.37% | — | Wp-appboxAI | 24/12/2024 | 17/6/2026 | The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Aplazada | Media (5.3) | 0.39% | — | Popup BOXAI | 16/11/2024 | 17/6/2026 | The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to… |