Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.21%—10up Safe SVGAI30/9/202630/9/2026
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
AplazadaMedia (6.5)0.18%—10up Safe SVGAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
AnalizadaMedia (4.8)0.31%—10up Safe SVG7/11/202417/6/2026
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.
ModificadaMedia (6.1)1.2%—10up Safe SVG18/4/202217/6/2026
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of…
ModificadaAlta (7.5)2.6%—10up Safe SVG11/11/201917/6/2026
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
ModificadaAlta (7.5)2.6%—10up Safe SVG11/11/201917/6/2026
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.