Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | 10up Safe SVGAI | 30/9/2026 | 30/9/2026 | Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | 10up Safe SVGAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. | |
| Analizada | Media (4.8) | 0.31% | — | 10up Safe SVG | 7/11/2024 | 17/6/2026 | The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data. | |
| Modificada | Media (6.1) | 1.2% | — | 10up Safe SVG | 18/4/2022 | 17/6/2026 | The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of… | |
| Modificada | Alta (7.5) | 2.6% | — | 10up Safe SVG | 11/11/2019 | 17/6/2026 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes. | |
| Modificada | Alta (7.5) | 2.6% | — | 10up Safe SVG | 11/11/2019 | 17/6/2026 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring. |