Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.37%—Keywordrush Content EGGAI30/9/202630/9/2026
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
AplazadaMedia (6.8)0.24%—Keywordrush Content EGGAI30/9/202630/9/2026
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary…
AplazadaMedia (5.5)0.71%—Cleverbrush FrameworkAI25/8/202628/9/2026
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been…
Pendiente de análisisMedia (6.9)0.53%—BrushfireAI21/8/202626/8/2026
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.
AplazadaMedia (5.3)0.36%—GNU RushAI21/8/202627/8/2026
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AplazadaAlta (8.1)1.2%—Keywordrush Content EGGAI5/8/202612/8/2026
The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through…
AnalizadaMedia (6.9)0.18%—Pixarra Twistedbrush PRO Studio21/3/202617/6/2026
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application…
AnalizadaMedia (6.9)0.19%—Pixarra Twistedbrush PRO Studio21/3/202617/6/2026
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to trigger a buffer overflow that causes the…
AnalizadaMedia (6.9)0.18%—Pixarra Twistedbrush PRO Studio21/3/202617/6/2026
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder…
AnalizadaCrítica (9.8)0.65%—Mediacrush3/2/202617/6/2026
An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint.
AplazadaMedia (4.3)0.30%—Crush Pics Image OptimizerAI14/1/202617/6/2026
The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple functions in all versions up to, and including, 1.8.7. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (5.4)0.12%—Semrush CY LTD Semrush Content ToolkitAI16/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cross Site Request Forgery.This issue affects Semrush Content Toolkit: from n/a through <= 1.1.32.
AplazadaMedia (6.9)0.35%—MediacrushAI1/12/20253/9/2026
A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.
AnalizadaMedia (6.1)0.23%—Crushftp12/11/202517/6/2026
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection.
AnalizadaMedia (4.1)0.27%—Crushftp7/11/202517/6/2026
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.
AplazadaAlta (8.8)0.20%—Tusko Trush Advanced Custom Fields CPT Options PagesAI22/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.
AplazadaAlta (7.2)0.47%—Keywordrush Content EGGAI14/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in keywordrush Content Egg content-egg allows Object Injection.This issue affects Content Egg: from n/a through <= 7.0.0.
AplazadaBaja (1.9)0.13%—Riderlike Fruit Crush-brain APPAI4/8/202517/6/2026
A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.fruitcrush.fun. The manipulation leads to improper export of android application components. It…
AnalizadaCrítica (9.8)95%⚠ Explotación activaCrushftp18/7/202517/6/2026
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
AplazadaAlta (8.1)0.76%—Bzotheme FitrushAI9/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Fitrush allows PHP Local File Inclusion. This issue affects Fitrush: from n/a through 1.3.4.
ModificadaMedia (5)18%—Crushftp15/4/202517/6/2026
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
ModificadaMedia (5)9.4%—Crushftp15/4/202517/6/2026
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.
AnalizadaCrítica (9.8)100%⚠ Explotación activaCrushftp3/4/202517/6/2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3)…
AnalizadaCrítica (9.8)0.82%—Crushftp10/12/202417/6/2026
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
AnalizadaCrítica (9.1)0.31%—Appleboy Gorush6/8/202417/6/2026
An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.