Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.60%—Pgvector Project Pgvector29/7/202620/8/2026
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
ModificadaAlta (7.7)0.52%—Validator Project Validator27/11/202514/7/2026
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This…
ModificadaMedia (6.1)0.32%—Validator Project Validator30/9/20255/7/2026
A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open…
AnalizadaCrítica (9.8)7.8%—WP Mobile Detector Project WP Mobile Detector19/7/202517/6/2026
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code…
AnalizadaAlta (7.3)0.39%—Ueditor Project Ueditor23/4/20251/10/2026
Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
AnalizadaMedia (5.9)0.32%—Google Maps\ Store Locator Project16/4/202517/6/2026
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
AnalizadaAlta (8.8)0.62%—Umeditor Project Umeditor3/3/202517/6/2026
A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.
ModificadaMedia (5.3)0.35%—WP Dummy Content Generator Project WP Dummy Content Generator14/6/202417/6/2026
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0.
ModificadaMedia (6.1)0.24%—Baidu-tongji-generator Project Baidu-tongji-generator13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.
ModificadaMedia (6.1)0.37%—Login Configurator Project Login Configurator30/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
ModificadaMedia (4.8)0.37%—Login Configurator Project Login Configurator25/7/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
ModificadaMedia (4.8)0.37%—Custom Post Type Generator Project Custom Post Type Generator18/7/202317/6/2026
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 versions.
ModificadaMedia (6.1)0.72%—Login Configurator Project Login Configurator17/7/202317/6/2026
The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.
ModificadaAlta (8.8)0.33%—WP Dummy Content Generator Project WP Dummy Content Generator10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.
ModificadaMedia (4.8)0.54%—Image Protector Project Image Protector10/7/202317/6/2026
The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (6.1)0.39%—Meldekarten Generator Project Meldekarten Generator27/6/202317/6/2026
Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after…
ModificadaMedia (4.8)0.37%—Vigilantor Project Vigilantor22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Drew Phillips VigilanTor plugin <= 1.3.10 versions.
ModificadaMedia (4.3)0.57%—Ooohboi Steroids FOR Elementor Project Ooohboi Steroids FOR Elementor9/6/202317/6/2026
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
AnalizadaMedia (4.8)0.37%—Baidu-tongji-generator Project Baidu-tongji-generator18/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions.
ModificadaMedia (6.1)0.55%—Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator31/3/202317/6/2026
A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.74%—Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator31/3/202317/6/2026
A vulnerability has been found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as critical. Affected by this vulnerability is the function get_scale of the file Master.php. The manipulation of the argument perc leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaAlta (7.5)0.64%—Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator31/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page with the input php://filter/read=convert.base64-encode/resource=grade_table leads to information…
ModificadaMedia (6.1)0.55%—Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator30/3/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Grade Point Average GPA Calculator 1.0. This affects an unknown part of the file index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaMedia (6.5)1.0%—Ooohboi Steroids FOR Elementor Project Ooohboi Steroids FOR Elementor27/3/202317/6/2026
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
ModificadaMedia (6.1)0.32%—Quickentity Editor Project Quickentity Editor6/3/202317/6/2026
quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.…