Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.2) | 0.10% | — | Sparkle-project Sparkle | 21/7/2026 | 5/8/2026 | Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach… | |
| Analizada | Media (6.1) | 0.34% | — | Sparkle-project Sparkle | 21/7/2026 | 5/8/2026 | Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself a symbolic link, but does not detect symlinks deeper in the relative path.… | |
| Aplazada | Media (4.3) | 0.18% | — | Sparkle WP MetrostoreAI | 11/6/2026 | 26/9/2026 | Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2. | |
| Aplazada | Media (4.3) | 0.19% | — | Sparklewpthemes Fitness FSEAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6. | |
| Aplazada | Media (4.3) | 0.19% | — | Sparklewpthemes Hello FSEAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6. | |
| Aplazada | Media (5.4) | 0.20% | — | Sparklewpthemes Sparkle FSEAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sparkle FSE: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.4) | 0.20% | — | Sparklewpthemes Construction LightAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Light: from n/a through <= 1.6.7. | |
| Aplazada | Alta (8.8) | 0.19% | — | Sparkle-project SparkleAI | 16/9/2025 | 17/6/2026 | The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege escalation to root… | |
| Aplazada | Media (4.8) | 0.17% | — | Sparkle-project SparkleAI | 16/9/2025 | 17/6/2026 | The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker… | |
| Aplazada | Media (6.5) | 0.21% | — | Sparklewpthemes Blogger BuzzAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Blogger Buzz blogger-buzz allows Stored XSS.This issue affects Blogger Buzz: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.5) | 0.24% | — | Sparklewpthemes Fitness ParkAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Fitness Park fitness-park allows DOM-Based XSS.This issue affects Fitness Park: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.24% | — | Sparklewpthemes Spark MultipurposeAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Spark Multipurpose spark-multipurpose allows DOM-Based XSS.This issue affects Spark Multipurpose: from n/a through <= 1.0.7. | |
| Aplazada | Media (4.3) | 0.26% | — | Sparklewpthemes Hello FSE BlogAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE Blog: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.5) | 1.1% | — | Jakub Glos Sparkle Elementor KITAI | 4/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows PHP Local File Inclusion.This issue affects Sparkle Elementor Kit: from n/a through <= 2.0.9. | |
| Analizada | Media (6.8) | 0.90% | — | Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation | 4/2/2025 | 17/6/2026 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks. | |
| Aplazada | Media (4.3) | 0.40% | — | Sparkle Themes Blogger BuzzAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2. | |
| Aplazada | Media (4.3) | 0.39% | — | Sparkle Themes ChankheAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle Themes Chankhe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chankhe: from n/a through 1.0.5. | |
| Aplazada | Media (6.5) | 0.29% | — | Jakub Glos Sparkle Elementor KITAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows DOM-Based XSS.This issue affects Sparkle Elementor Kit: from n/a through <= 2.0.9. | |
| Modificada | Media (6.5) | 0.50% | — | Wpneuron Sparkle Demo Importer | 22/6/2024 | 17/6/2026 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Media (4.3) | 0.41% | — | Sparkle WP EditorialmagAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9. | |
| Aplazada | Media (4.3) | 0.38% | — | Sparkle WP EducenterAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5. | |
| Modificada | Alta (8.8) | 1.4% | — | Jquery-sparkle Project Jquery-sparkle | 23/4/2021 | 17/6/2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype. | |
| Modificada | Alta (7.8) | 2.6% | — | Winsparkle | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Alta (10) | 5.8% | — | Milan Mimica Sparklet | 13/7/2006 | 16/6/2026 | Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname. | |
| Modificada | Media (4.3) | 1.2% | — | Sparkleblog | 30/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field. |