Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.18% | — | Google TAG Project Google TAG | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8. | |
| Analizada | Media (4.8) | 0.23% | — | Google TAG Project Google TAG | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8. | |
| Modificada | Media (4.8) | 0.37% | — | Bing Site Verification Plugin Using Meta TAG Project Bing Site Verification Plugin Using Meta TAG | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Himanshu Bing Site Verification plugin using Meta Tag plugin <= 1.0 versions. | |
| Modificada | Media (4.8) | 0.61% | — | Auto More TAG Project Auto More TAG | 8/8/2022 | 17/6/2026 | The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.3) | 1.2% | — | Photo TAG Project Photo TAG | 11/7/2022 | 17/6/2026 | The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.5) | 1.1% | — | TAG Project TAG | 28/12/2020 | 17/6/2026 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData. | |
| Modificada | Media (6.5) | 1.1% | — | TAG Project TAG | 28/12/2020 | 17/6/2026 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame. | |
| Modificada | Media (6.5) | 1.1% | — | TAG Project TAG | 28/12/2020 | 17/6/2026 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame. | |
| Modificada | Media (6.5) | 1.1% | — | TAG Project TAG | 28/12/2020 | 17/6/2026 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame. | |
| Modificada | Alta (8.8) | 0.65% | — | Jayj Quicktag Project Jayj Quicktag | 16/8/2019 | 17/6/2026 | The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 2.7% | — | Facetag Project Facetag | 26/2/2018 | 17/6/2026 | ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action. | |
| Modificada | Media (6.1) | 1.4% | — | Facetag Project Facetag | 26/2/2018 | 17/6/2026 | The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action. | |
| Modificada | Media (5.5) | 1.4% | — | Libid3tag Project Libid3tag | 31/7/2017 | 17/6/2026 | The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file. | |
| Modificada | Media (5.5) | 1.5% | — | Libid3tag Project Libid3tag | 31/7/2017 | 17/6/2026 | The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file. |