Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.19%—Commoninja Videos Sync PDFAI10/5/202617/6/2026
WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options…
AplazadaMedia (5.3)0.29%—Madrasthemes MAS VideosAI13/3/202617/6/2026
Missing Authorization vulnerability in MadrasThemes MAS Videos masvideos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MAS Videos: from n/a through <= 1.3.2.
AplazadaAlta (8.8)0.34%—Videospirecore Theme PluginAI11/2/202617/6/2026
The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.6. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated…
AplazadaMedia (4.3)0.23%—Webdevstudios Automatic Featured Images From VideosAI23/1/202617/6/2026
Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7.
AplazadaMedia (5.3)0.25%—Channelize Live Shopping AND Shoppable Videos FOR WoocommerceAI31/12/202517/6/2026
Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0.
AplazadaAlta (7.5)0.39%—Madrasthemes MAS VideosAI30/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MadrasThemes MAS Videos masvideos allows PHP Local File Inclusion.This issue affects MAS Videos: from n/a through <= 1.3.4.
AplazadaMedia (6.4)0.24%—Kevinweber Lazy Load FOR VideosAI27/8/202517/6/2026
The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, 2.18.7 due to insufficient input sanitization and output escaping. The plugin’s JavaScript registration handlers read the client‑supplied 'data-video-title' and…
AplazadaMedia (6.5)0.21%—Perteus Porn Videos EmbedAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perteus Porn Videos Embed porn-videos-embed allows Stored XSS.This issue affects Porn Videos Embed: from n/a through <= 0.9.1.
AplazadaAlta (7.5)0.29%—Enguerranws Import Youtube Videos AS WP PostAI20/6/202517/6/2026
Missing Authorization vulnerability in enguerranws Import YouTube videos as WP Posts import-youtube-videos-as-wp-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Import YouTube videos as WP Posts: from n/a through <= 2.1.
AnalizadaAlta (8.1)0.22%—Webgarh Offload Videos15/5/202517/6/2026
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
AplazadaAlta (7.1)0.29%—Ilghera Related-videos-for-jw-playerAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilGhera Related Videos for JW Player related-videos-for-jw-player allows Reflected XSS.This issue affects Related Videos for JW Player: from n/a through <= 1.2.0.
AplazadaAlta (7.1)0.25%—Aviplugins VideosAI4/4/202517/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows Reflected XSS.This issue affects Videos: from n/a through 1.0.5.
AplazadaMedia (4.3)0.33%—Webdevstudios Automatic Featured Images From VideosAI1/4/202517/6/2026
Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.4.
AplazadaMedia (6.4)0.33%—Responsive VideosAI4/12/202417/6/2026
The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)1.1%—Lazy Load Videos AND Sticky ControlAI21/11/202417/6/2026
The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AplazadaMedia (6.1)0.38%—Embed Videos AND Respect PrivacyAI11/10/202417/6/2026
The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaAlta (8.8)0.21%—Kevinweber Lazy Load FOR Videos16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kevin Weber Lazy Load for Videos plugin <= 2.18.2 versions.
ModificadaMedia (4.8)0.37%—Gingertech External Videos14/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <= 2.0.1 versions.
ModificadaAlta (8.8)0.26%—Digitalinspiration Google XML Sitemap FOR Videos15/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
ModificadaAlta (7)0.35%—Getvideostream Videostream17/5/202317/6/2026
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.
ModificadaCrítica (9.3)1.4%—Videoserver Project Videoserver11/7/202217/6/2026
The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (7.5)11%—Commoninja Videos Sync PDF25/4/202217/6/2026
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues
ModificadaAlta (8.8)1.0%—Meomundo Related Youtube Videos5/7/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (5.4)0.64%—Cisco Videoscape Anyres Live8/3/201817/6/2026
A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of…
ModificadaCrítica (9.8)2.7%—Allvideos Reloaded Project Allvideos Reloaded17/2/201817/6/2026
SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.