Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.18%—Google TAG Project Google TAG31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
AnalizadaMedia (4.8)0.23%—Google TAG Project Google TAG31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
ModificadaMedia (4.8)0.37%—Bing Site Verification Plugin Using Meta TAG Project Bing Site Verification Plugin Using Meta TAG3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Himanshu Bing Site Verification plugin using Meta Tag plugin <= 1.0 versions.
ModificadaMedia (4.8)0.61%—Auto More TAG Project Auto More TAG8/8/202217/6/2026
The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.3)1.2%—Photo TAG Project Photo TAG11/7/202217/6/2026
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (6.5)1.1%—TAG Project TAG28/12/202017/6/2026
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
ModificadaMedia (6.5)1.1%—TAG Project TAG28/12/202017/6/2026
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
ModificadaMedia (6.5)1.1%—TAG Project TAG28/12/202017/6/2026
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.
ModificadaMedia (6.5)1.1%—TAG Project TAG28/12/202017/6/2026
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.
ModificadaAlta (8.8)0.65%—Jayj Quicktag Project Jayj Quicktag16/8/201917/6/2026
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
ModificadaCrítica (9.8)2.7%—Facetag Project Facetag26/2/201817/6/2026
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
ModificadaMedia (6.1)1.4%—Facetag Project Facetag26/2/201817/6/2026
The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.
ModificadaMedia (5.5)1.4%—Libid3tag Project Libid3tag31/7/201717/6/2026
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
ModificadaMedia (5.5)1.5%—Libid3tag Project Libid3tag31/7/201717/6/2026
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.