Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.21%—Live Copy PasteAI23/9/202623/9/2026
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
AplazadaAlta (8.7)0.56%—RustypasteAI13/9/202623/9/2026
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.
AplazadaMedia (4.3)0.27%—Live Copy Paste FOR ElementorAI26/6/202629/9/2026
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
AplazadaAlta (7.5)0.46%—Anna-is-cute PasteAI15/6/202617/6/2026
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AplazadaAlta (8.1)0.48%—Themepaste Admin Safety GuardAI19/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through <= 1.2.6.
AplazadaMedia (6.5)0.37%—Rami Yushuvaev Pastebin-embedAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rami Yushuvaev Pastebin pastebin-embed allows Stored XSS.This issue affects Pastebin: from n/a through <= 1.5.
ModificadaMedia (6.1)0.52%—Darrennathanael Dpaste1/12/202317/6/2026
dpaste is an open source pastebin application written in Python using the Django framework. A security vulnerability has been identified in the expires parameter of the dpaste API, allowing for a POST Reflected XSS attack. This vulnerability can be exploited by an attacker to execute arbitrary JavaScript code in the…
ModificadaMedia (6.1)0.51%—Opensuse Paste7/2/202317/6/2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.
ModificadaMedia (5.3)0.77%—Pastebinit Project Pastebinit30/12/202217/6/2026
A vulnerability was found in pastebinit up to 0.2.2 and classified as problematic. Affected by this issue is the function pasteHandler of the file server.go. The manipulation of the argument r.URL.Path leads to path traversal. Upgrading to version 0.2.3 is able to address this issue. The name of the patch is…
ModificadaMedia (6.1)1.7%—Paste-markdown Project Paste-markdown12/8/202117/6/2026
@github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string `<table>`, a **div** is dynamically created, and the clipboard content is copied into its **innerHTML**…
ModificadaMedia (6.5)1.7%—Ckeditor5-engineCkeditor5-fontCkeditor5-imageCkeditor5-list+429/4/202117/6/2026
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of…
ModificadaMedia (5.5)0.31%—KDE Paste Applet11/2/202016/6/2026
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
ModificadaAlta (8.4)0.56%—KDE Paste Applet11/2/202016/6/2026
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
ModificadaMedia (4.3)1.2%—Atmoner Php-pastebin3/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PHP-pastebin 2.1 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
ModificadaMedia (5.1)4.0%—Pythonpaste Paste1/5/201216/6/2026
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.
ModificadaMedia (4.3)2.3%—Pythonpaste Paste6/11/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3)…
ModificadaMedia (6.8)1.9%—Pastelcms24/4/200916/6/2026
Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter.
ModificadaMedia (6.8)0.93%—Pastelcms24/4/200916/6/2026
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.
ModificadaMedia (4.3)1.1%—Patrick Matthai Pnopaste17/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%—Cccp-common-clan-portal-pasterbin Cccp Pastebin6/4/200916/6/2026
Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE:…
ModificadaMedia (6.8)1.1%—Gnopaste9/2/200716/6/2026
PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter. NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable
ModificadaAlta (7.5)8.2%—Gnopaste6/6/200616/6/2026
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.