Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.52% | — | Silk Themes Newspapers XAI | 31/8/2026 | 1/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | |
| Aplazada | Media (5.3) | 0.28% | — | Silkentrepreneur WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Media (6.5) | 0.20% | — | Silkypress Multi-step Checkout FOR WoocommerceAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SilkyPress Multi-Step Checkout for WooCommerce wp-multi-step-checkout allows DOM-Based XSS.This issue affects Multi-Step Checkout for WooCommerce: from n/a through <= 2.33. | |
| Modificada | Media (6.1) | 0.47% | — | Qt-users Silk | 20/2/2023 | 17/6/2026 | A vulnerability was found in qt-users-jp silk 0.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file contents/root/examples/header.qml. The manipulation of the argument model.key/model.value leads to cross site scripting. The attack can be initiated remotely. The name of the… | |
| Modificada | Media (5.3) | 1.4% | — | Silkypress WP Image Zoom | 19/7/2021 | 17/6/2026 | The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard | |
| Modificada | Crítica (9.8) | 2.0% | — | Silk-v3-decoder Project Silk-v3-decoder | 9/9/2020 | 17/6/2026 | The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow. | |
| Modificada | Media (6.5) | 1.0% | — | Silkypress Image Zoom | 26/6/2018 | 17/6/2026 | WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of service. This attack appear to be exploitable via Can be triggered intentionally (or unintentionally via CSRF) by any logged in user. This vulnerability appears to have… | |
| Modificada | Alta (8.1) | 0.98% | — | Cloudfoundry Silk-release | 27/3/2018 | 17/6/2026 | Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the network regardless of the configured… | |
| Modificada | Media (6.1) | 1.5% | — | Silkypress Simple Custom CSS AND JS | 2/8/2017 | 17/6/2026 | Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 4.2% | — | Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+2 | 4/9/2004 | 16/6/2026 | Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets. |