Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.29% | — | Drupal ScreenshotAI | 2/9/2026 | 2/9/2026 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | |
| Pendiente de análisis | Alta (7.3) | 0.29% | — | Drupal ScreenshotAI | 2/9/2026 | 5/10/2026 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | |
| Aplazada | Baja (2.1) | 2.4% | — | Moussaabbadla Code-screenshot-mcpAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Screenshot-desktopAI | 19/8/2025 | 17/6/2026 | screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with… | |
| Aplazada | Alta (7.7) | 0.28% | — | Glpi Screenshot PluginAI | 5/8/2025 | 17/6/2026 | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2. | |
| Aplazada | Media (6.2) | 0.20% | — | Datapatrol Screenshot WatermarkAI | 17/4/2025 | 17/6/2026 | An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information. NOTE: the Supplier disputes the Print Job Watermark Bypass claim because the watermark is added by hooking into the OS printing mechanism, and thus is not supposed to… | |
| Aplazada | Alta (7.1) | 0.31% | — | Rico Macchi WP Featured ScreenshotAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot wp-featured-screenshot allows Reflected XSS.This issue affects WP Featured Screenshot: from n/a through <= 1.3. | |
| Aplazada | Media (6.4) | 0.34% | — | JSM Screenshot Machine ShortcodeAI | 18/1/2025 | 17/6/2026 | The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (6.1) | 0.27% | — | Tidaweb Tida URL Screenshot | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tidaweb Tida URL Screenshot tida-url-screenshot allows Reflected XSS.This issue affects Tida URL Screenshot: from n/a through <= 1.0.1. | |
| Modificada | Media (6.6) | 0.71% | — | Iobit Advanced System CareIobit Driver BoosterIobit Itop Screen RecorderIobit Itop Screenshot+1 | 6/7/2022 | 9/7/2026 | IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install… | |
| Modificada | Media (5.4) | 0.62% | — | Prothemedesign Browser Screenshots | 12/7/2021 | 17/6/2026 | The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped. |