Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.88% | — | Seotoaster | 21/3/2026 | 17/6/2026 | SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arbitrary files by manipulating path parameters in backend theme endpoints. Attackers can send POST requests to /backend/backend_theme/editcss/ or /backend/backend_theme/editjs/ with directory traversal… | |
| Analizada | Media (5.3) | 0.35% | — | Toastwebsites Find Unused Images | 11/11/2025 | 17/6/2026 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's… | |
| Aplazada | Alta (7.1) | 0.25% | — | Toast Plugins Toast Mobile MenuAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Toast Mobile Menu toast-responsive-menu allows Stored XSS.This issue affects Toast Mobile Menu: from n/a through <= 1.0.8. | |
| Aplazada | Media (4.3) | 0.13% | — | Toast Plugins AnimatorAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator scroll-triggered-animations allows Cross Site Request Forgery.This issue affects Animator: from n/a through <= 3.0.16. | |
| Aplazada | Media (6.5) | 0.14% | — | Tomontoast Drop CapsAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tomontoast Drop Caps drop-caps allows Stored XSS.This issue affects Drop Caps: from n/a through <= 2.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Toast Plugins Internal Link OptimiserAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Stored XSS.This issue affects Internal Link Optimiser: from n/a through <= 5.1.3. | |
| Aplazada | Media (6.5) | 0.31% | — | Toast Plugins Internal Link OptimiserAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Link Optimiser: from n/a through <= 5.1.2. | |
| Aplazada | Media (6.5) | 0.40% | — | Toast Plugins AnimatorAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Toast Plugins Animator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animator: from n/a through 3.0.10. | |
| Aplazada | Alta (7.1) | 0.29% | — | Toast Plugins AnimatorAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Animator scroll-triggered-animations allows Reflected XSS.This issue affects Animator: from n/a through <= 3.0.15. | |
| Aplazada | Alta (7.1) | 0.18% | — | Toast Plugins Sticky AnythingAI | 29/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything: from n/a through 2.1.5. | |
| Aplazada | Alta (7.1) | 0.18% | — | Toastie Studio Woocommerce Social Media Share ButtonsAI | 2/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a through 1.3.0. | |
| Aplazada | Alta (7.1) | 0.33% | — | Toast Plugins Sticky AnythingAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Sticky Anything.This issue affects Sticky Anything: from n/a through 2.1.5. | |
| Modificada | Media (6.1) | 0.53% | — | Nhncloud Toast UI Chart | 22/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 4.2.0 is able to address this issue.… | |
| Modificada | Media (6.1) | 0.65% | — | NHN Toast UI Grid | 22/9/2022 | 17/6/2026 | Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workarounds. | |
| Modificada | Alta (7.5) | 1.8% | — | Olivetoast Documents PRO File Viewer | 19/1/2013 | 16/6/2026 | Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to read or delete files by leveraging guest access. | |
| Modificada | Media (4.3) | 1.1% | — | Olivetoast Documents PRO File Viewer | 19/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Seotoaster | 25/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member. | |
| Modificada | Media (6.2) | 0.37% | — | Roxio Toast | 14/9/2006 | 16/6/2026 | Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary files, including dejavu_manual.rb, which are executed with raised privileges. | |
| Modificada | Media (4.3) | 1.9% | — | Toast Forums | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter. | |
| Modificada | Media (4.6) | 0.41% | — | Roxio Toast | 31/12/2004 | 16/6/2026 | Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via format string specifiers in the extension argument. |