Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.45%—Wikimedia MediawikiAIWikimedia Score ExtensionAI7/4/202621/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.
AplazadaMedia (6.4)0.24%—Simple Football ScoreboardAI21/3/202617/6/2026
The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreboard' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.36%—Scoreboard FOR Html5 Games LiteAI21/3/202617/6/2026
The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small…
AplazadaAlta (8.1)0.58%—Mikado-themes Topscore - Sports Wordpress ThemeAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through <= 1.2.
AnalizadaAlta (8.2)1.0%—Underscorejs Underscore3/3/202617/6/2026
Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be…
AplazadaMedia (4.3)0.17%—Daext Soccer Live ScoresAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Soccer Live Scores allows Cross Site Request Forgery. This issue affects Soccer Live Scores: from n/a through 1.0.5.
AplazadaMedia (6.5)0.27%—Jobscore JOB ManagerAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JobScore Job Manager job-manager-by-jobscore allows Stored XSS.This issue affects Job Manager: from n/a through <= 2.2.
AplazadaMedia (6.8)0.35%—Musescore StudioAI17/3/202517/6/2026
A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.
AplazadaAlta (7.5)0.50%—Underscore ContribAI5/2/202517/6/2026
A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AplazadaMedia (6.4)0.35%—Cricket Live ScoreAI14/12/202417/6/2026
The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (6.5)0.26%—Dogrow Simple Baseball ScoreboardAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dogrow Simple Baseball Scoreboard simple-baseball-scoreboard allows Stored XSS.This issue affects Simple Baseball Scoreboard: from n/a through <= 1.3.
AnalizadaAlta (7.3)0.52%—Snapchat Lenscore31/5/202417/6/2026
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
AnalizadaAlta (7.8)0.53%—Musescore3/5/202417/6/2026
MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MuseScore. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
ModificadaMedia (5.4)0.41%—Livescore Bzscore14/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in livescore.Bz BZScore – Live Score plugin <= 1.03 versions.
ModificadaAlta (8.8)0.69%—Longmenedutech Score Query System26/10/202317/6/2026
A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument stuIdCard leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.5)0.89%—Underscore-keypath Project Underscore-keypath1/8/202317/6/2026
Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.
ModificadaCrítica (9.8)1.2%—Oscore28/7/202317/6/2026
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
ModificadaMedia (5.4)0.37%—SAP Customer Relationship Management Webclient UISAP S4fndSapscore9/5/202317/6/2026
SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After…
ModificadaCrítica (9.8)2.3%💥 PoCMediawiki Score15/4/202317/6/2026
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted…
ModificadaAlta (7)0.36%—Musescore28/3/202317/6/2026
Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.
ModificadaMedia (5.4)0.45%—SAP S/4hanaSapscore12/7/202217/6/2026
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on…
ModificadaCrítica (9.3)1.6%—Scorelab Openmf11/7/202217/6/2026
The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.8)1.1%—Clever Underscore.deep28/6/202217/6/2026
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and pass it to `deepFromFlat`, which would pollute any future Objects created. Any…
ModificadaAlta (7.5)1.1%—Underscore-99xp Project Underscore-99xp24/6/202217/6/2026
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.
ModificadaMedia (4.3)0.45%—WP Performance Score Booster Project WP Performance Score Booster17/11/202117/6/2026
The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
Orbitaley — Vulnerabilidades