Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.51% | — | Tumf Mcp-text-editorAI | 9/7/2026 | 9/7/2026 | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_text_editor/text_editor.py. Such manipulation of the argument file_path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed… | |
| Aplazada | Media (6.4) | 0.16% | — | Media Library ALT Text EditorAI | 7/3/2026 | 17/6/2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.3) | 0.83% | — | Phphtmledit Rich Text Editor | 13/1/2026 | 17/6/2026 | CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal… | |
| Aplazada | Media (4.8) | 0.28% | — | Asustor ADMAIAsustor Text EditorAI | 14/7/2025 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other sensitive information retained by the browser and used with the… | |
| Aplazada | Media (6.5) | 0.38% | — | Richtexteditor Rich Text EditorAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.14% | — | Richtexteditor Rich Text EditorAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor richtexteditor allows Stored XSS.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.9) | 0.78% | — | Govind Visual Text EditorAI | 26/3/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.This issue affects Visual Text Editor: from n/a through <= 1.2.1. | |
| Modificada | Media (5.4) | 0.61% | — | Summernote Rich Text Editor | 18/9/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component. | |
| Modificada | Media (4.3) | 1.3% | — | Webwizguide WEB WIZ Rich Text Editor | 30/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modificada | Media (6.4) | 2.6% | — | WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors. | |
| Modificada | Media (5) | 3.9% | — | WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action. | |
| Modificada | Media (5) | 4.9% | — | Webwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a… | |
| Modificada | Media (4.3) | 1.0% | — | Bruce Corkhill WEB WIZ Rich Text Editor | 12/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document. | |
| Modificada | Alta (10) | 5.2% | — | FTE Text EditorDebian Linux | 4/5/2004 | 16/6/2026 | Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code. |