Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.73% | — | SqueezeAI | 10/8/2026 | 26/8/2026 | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code… | |
| Aplazada | Media (5) | 0.34% | — | SqueezeAI | 13/3/2026 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7. | |
| Aplazada | Baja (2.7) | 0.51% | — | Bogdan Bendziukov SqueezeAI | 9/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze squeeze allows Retrieve Embedded Sensitive Data.This issue affects Squeeze: from n/a through <= 1.6. | |
| Aplazada | Crítica (9.1) | 0.66% | — | Bogdan Bendziukov SqueezeAI | 9/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Malicious Files.This issue affects Squeeze: from n/a through <= 1.6. | |
| Modificada | Alta (7.2) | 0.49% | — | Squeeze Project Squeeze | 21/6/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a through 1.4. | |
| Modificada | Media (4.3) | 2.0% | — | Instasqueeze Sexy Squeeze Pages | 2/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the InstaSqueeze Sexy Squeeze Pages plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to lp/index.php. | |
| Modificada | Media (5.1) | 4.1% | — | Speedproject SpeedcommanderSpeedproject Squeez | 29/4/2006 | 16/6/2026 | Multiple buffer overflows in (1) CxAce60.dll and (2) CxAce60u.dll in SpeedProject Squeez 5.10 Build 4460, and SpeedCommander 10.52 Build 4450 and 11.01 Build 4450, allow user-assisted remote attackers to execute arbitrary code via an ACE archive that contains a file with a long filename. | |
| Modificada | Media (5) | 1.8% | — | Speedproject SpeedcommanderSpeedproject SqueezSpeedproject Zipstar | 25/2/2006 | 16/6/2026 | Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive. | |
| Modificada | Media (5.1) | 3.3% | — | Speedproject SpeedcommanderSpeedproject Squeez | 26/11/2005 | 16/6/2026 | Stack-based buffer overflow in (1) CxUux60.dll and (2) CxUux60u.dll, as used in SpeedProject products including (a) Squeez 5.0 Build 4285, and (b) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename. | |
| Modificada | Media (5.1) | 2.6% | — | Speedproject SpeedcommanderSpeedproject SqueezSpeedproject Zipstar | 26/11/2005 | 16/6/2026 | Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a… |