Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.72% | — | Digitialpixies Oauth ClientAI | 16/8/2026 | 26/8/2026 | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Digitialpixies Oauth ClientAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | |
| Aplazada | Media (6.9) | 0.20% | — | RattlerAIRattler Conda TypesAIConda PixiAIConda MambaAI+1 | 21/7/2026 | 23/7/2026 | Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto the install prefix and writes an executable Python script. A malicious… | |
| Modificada | Media (6.5) | 0.36% | — | Digitialpixies Oauth Client | 14/11/2022 | 17/6/2026 | The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions. | |
| Modificada | Media (4.8) | 0.53% | — | Digitialpixies Oauth Client | 14/11/2022 | 17/6/2026 | The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Crítica (9.8) | 1.5% | — | Pixie Project Pixie | 19/11/2019 | 17/6/2026 | Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization. | |
| Modificada | Crítica (10) | 2.6% | — | Vebto Pixie - Image Editor | 25/9/2017 | 17/6/2026 | Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php. | |
| Modificada | Crítica (9.8) | 5.0% | — | Lucidcrew Pixie | 3/4/2017 | 17/6/2026 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | |
| Modificada | Media (6.1) | 1.2% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | |
| Modificada | Media (4.3) | 1.4% | — | Lucidcrew Pixie | 4/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/. | |
| Modificada | Media (6.9) | 0.35% | — | Pixia | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Pixia 4.70j allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pxa file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.7% | — | Getpixie PixieLucidcrew Pixie | 8/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI. | |
| Modificada | Media (4.3) | 3.5% | — | Zespia Pixiv Custom | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | |
| Modificada | Media (5) | 1.9% | — | Lucidcrew Pixie | 24/9/2011 | 16/6/2026 | Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files. | |
| Modificada | Media (4.3) | 3.7% | — | Getpixie Pixie CMS | 26/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Getpixie Pixie CMS | 26/3/2009 | 16/6/2026 | SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request. | |
| Modificada | Alta (7.5) | 1.1% | — | Getpixie Pixie CMS | 26/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |