Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.2)0.10%—Sparkle-project Sparkle21/7/20265/8/2026
Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `_performedStage1Installation = YES`, new connections to the registered Mach…
AnalizadaMedia (6.1)0.34%—Sparkle-project Sparkle21/7/20265/8/2026
Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself a symbolic link, but does not detect symlinks deeper in the relative path.…
AplazadaMedia (4.3)0.18%—Sparkle WP MetrostoreAI11/6/202626/9/2026
Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.
AplazadaMedia (4.3)0.19%—Sparklewpthemes Fitness FSEAI19/2/202617/6/2026
Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fitness FSE: from n/a through <= 1.0.6.
AplazadaMedia (4.3)0.19%—Sparklewpthemes Hello FSEAI19/2/202617/6/2026
Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE: from n/a through <= 1.0.6.
AplazadaMedia (5.4)0.20%—Sparklewpthemes Sparkle FSEAI18/12/202517/6/2026
Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sparkle FSE: from n/a through <= 1.0.9.
AplazadaMedia (5.4)0.20%—Sparklewpthemes Construction LightAI18/12/202517/6/2026
Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Light: from n/a through <= 1.6.7.
AplazadaAlta (8.8)0.19%—Sparkle-project SparkleAI16/9/202517/6/2026
The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege escalation to root…
AplazadaMedia (4.8)0.17%—Sparkle-project SparkleAI16/9/202517/6/2026
The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client allows the attacker…
AplazadaMedia (6.5)0.21%—Sparklewpthemes Blogger BuzzAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Blogger Buzz blogger-buzz allows Stored XSS.This issue affects Blogger Buzz: from n/a through <= 1.2.6.
AplazadaMedia (6.5)0.24%—Sparklewpthemes Fitness ParkAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Fitness Park fitness-park allows DOM-Based XSS.This issue affects Fitness Park: from n/a through <= 1.1.1.
AplazadaMedia (6.5)0.24%—Sparklewpthemes Spark MultipurposeAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Spark Multipurpose spark-multipurpose allows DOM-Based XSS.This issue affects Spark Multipurpose: from n/a through <= 1.0.7.
AplazadaMedia (4.3)0.26%—Sparklewpthemes Hello FSE BlogAI20/6/202517/6/2026
Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE Blog: from n/a through <= 1.0.6.
AplazadaAlta (7.5)1.1%—Jakub Glos Sparkle Elementor KITAI4/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows PHP Local File Inclusion.This issue affects Sparkle Elementor Kit: from n/a through <= 2.0.9.
AnalizadaMedia (6.8)0.90%—Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation4/2/202517/6/2026
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
AplazadaMedia (4.3)0.40%—Sparkle Themes Blogger BuzzAI9/12/202417/6/2026
Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2.
AplazadaMedia (4.3)0.39%—Sparkle Themes ChankheAI9/12/202417/6/2026
Missing Authorization vulnerability in Sparkle Themes Chankhe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chankhe: from n/a through 1.0.5.
AplazadaMedia (6.5)0.29%—Jakub Glos Sparkle Elementor KITAI30/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakub Glos Sparkle Elementor Kit sparkle-elementor-kit allows DOM-Based XSS.This issue affects Sparkle Elementor Kit: from n/a through <= 2.0.9.
ModificadaMedia (6.5)0.50%—Wpneuron Sparkle Demo Importer22/6/202417/6/2026
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AplazadaMedia (4.3)0.41%—Sparkle WP EditorialmagAI17/5/202417/6/2026
Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.
AplazadaMedia (4.3)0.38%—Sparkle WP EducenterAI25/3/202417/6/2026
Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
ModificadaAlta (8.8)1.4%—Jquery-sparkle Project Jquery-sparkle23/4/202117/6/2026
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.
ModificadaAlta (7.8)2.6%—Winsparkle9/6/201717/6/2026
Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.
ModificadaAlta (10)5.8%—Milan Mimica Sparklet13/7/200616/6/2026
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.
ModificadaMedia (4.3)1.2%—Sparkleblog30/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.