Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia Score ExtensionAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Score Extension allows Cross-Site Scripting (XSS). The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | |
| Aplazada | Media (6.4) | 0.24% | — | Simple Football ScoreboardAI | 21/3/2026 | 17/6/2026 | The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreboard' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.36% | — | Scoreboard FOR Html5 Games LiteAI | 21/3/2026 | 17/6/2026 | The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small… | |
| Aplazada | Alta (8.1) | 0.58% | — | Mikado-themes Topscore - Sports Wordpress ThemeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through <= 1.2. | |
| Analizada | Alta (8.2) | 1.0% | — | Underscorejs Underscore | 3/3/2026 | 17/6/2026 | Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be… | |
| Aplazada | Media (4.3) | 0.17% | — | Daext Soccer Live ScoresAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Soccer Live Scores allows Cross Site Request Forgery. This issue affects Soccer Live Scores: from n/a through 1.0.5. | |
| Aplazada | Media (6.5) | 0.27% | — | Jobscore JOB ManagerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JobScore Job Manager job-manager-by-jobscore allows Stored XSS.This issue affects Job Manager: from n/a through <= 2.2. | |
| Aplazada | Media (6.8) | 0.35% | — | Musescore StudioAI | 17/3/2025 | 17/6/2026 | A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file. | |
| Aplazada | Alta (7.5) | 0.50% | — | Underscore ContribAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Media (6.4) | 0.35% | — | Cricket Live ScoreAI | 14/12/2024 | 17/6/2026 | The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.26% | — | Dogrow Simple Baseball ScoreboardAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dogrow Simple Baseball Scoreboard simple-baseball-scoreboard allows Stored XSS.This issue affects Simple Baseball Scoreboard: from n/a through <= 1.3. | |
| Analizada | Alta (7.3) | 0.52% | — | Snapchat Lenscore | 31/5/2024 | 17/6/2026 | Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above. | |
| Analizada | Alta (7.8) | 0.53% | — | Musescore | 3/5/2024 | 17/6/2026 | MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MuseScore. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Modificada | Media (5.4) | 0.41% | — | Livescore Bzscore | 14/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in livescore.Bz BZScore – Live Score plugin <= 1.03 versions. | |
| Modificada | Alta (8.8) | 0.69% | — | Longmenedutech Score Query System | 26/10/2023 | 17/6/2026 | A vulnerability was found in Shaanxi Chanming Education Technology Score Query System 5.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument stuIdCard leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 0.89% | — | Underscore-keypath Project Underscore-keypath | 1/8/2023 | 17/6/2026 | Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”. | |
| Modificada | Crítica (9.8) | 1.2% | — | Oscore | 28/7/2023 | 17/6/2026 | oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument. | |
| Modificada | Media (5.4) | 0.37% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 9/5/2023 | 17/6/2026 | SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Mediawiki Score | 15/4/2023 | 17/6/2026 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted… | |
| Modificada | Alta (7) | 0.36% | — | Musescore | 28/3/2023 | 17/6/2026 | Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code. | |
| Modificada | Media (5.4) | 0.45% | — | SAP S/4hanaSapscore | 12/7/2022 | 17/6/2026 | Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on… | |
| Modificada | Crítica (9.3) | 1.6% | — | Scorelab Openmf | 11/7/2022 | 17/6/2026 | The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.8) | 1.1% | — | Clever Underscore.deep | 28/6/2022 | 17/6/2026 | Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and pass it to `deepFromFlat`, which would pollute any future Objects created. Any… | |
| Modificada | Alta (7.5) | 1.1% | — | Underscore-99xp Project Underscore-99xp | 24/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called. | |
| Modificada | Media (4.3) | 0.45% | — | WP Performance Score Booster Project WP Performance Score Booster | 17/11/2021 | 17/6/2026 | The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. |