Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.19% | — | Commoninja Videos Sync PDFAI | 10/5/2026 | 17/6/2026 | WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options… | |
| Aplazada | Media (5.3) | 0.29% | — | Madrasthemes MAS VideosAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in MadrasThemes MAS Videos masvideos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MAS Videos: from n/a through <= 1.3.2. | |
| Aplazada | Alta (8.8) | 0.34% | — | Videospirecore Theme PluginAI | 11/2/2026 | 17/6/2026 | The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.6. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.23% | — | Webdevstudios Automatic Featured Images From VideosAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.3) | 0.25% | — | Channelize Live Shopping AND Shoppable Videos FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Alta (7.5) | 0.39% | — | Madrasthemes MAS VideosAI | 30/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MadrasThemes MAS Videos masvideos allows PHP Local File Inclusion.This issue affects MAS Videos: from n/a through <= 1.3.4. | |
| Aplazada | Media (6.4) | 0.24% | — | Kevinweber Lazy Load FOR VideosAI | 27/8/2025 | 17/6/2026 | The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, 2.18.7 due to insufficient input sanitization and output escaping. The plugin’s JavaScript registration handlers read the client‑supplied 'data-video-title' and… | |
| Aplazada | Media (6.5) | 0.21% | — | Perteus Porn Videos EmbedAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perteus Porn Videos Embed porn-videos-embed allows Stored XSS.This issue affects Porn Videos Embed: from n/a through <= 0.9.1. | |
| Aplazada | Alta (7.5) | 0.29% | — | Enguerranws Import Youtube Videos AS WP PostAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in enguerranws Import YouTube videos as WP Posts import-youtube-videos-as-wp-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Import YouTube videos as WP Posts: from n/a through <= 2.1. | |
| Analizada | Alta (8.1) | 0.22% | — | Webgarh Offload Videos | 15/5/2025 | 17/6/2026 | The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack | |
| Aplazada | Alta (7.1) | 0.29% | — | Ilghera Related-videos-for-jw-playerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilGhera Related Videos for JW Player related-videos-for-jw-player allows Reflected XSS.This issue affects Related Videos for JW Player: from n/a through <= 1.2.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Aviplugins VideosAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows Reflected XSS.This issue affects Videos: from n/a through 1.0.5. | |
| Aplazada | Media (4.3) | 0.33% | — | Webdevstudios Automatic Featured Images From VideosAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.4. | |
| Aplazada | Media (6.4) | 0.33% | — | Responsive VideosAI | 4/12/2024 | 17/6/2026 | The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 1.1% | — | Lazy Load Videos AND Sticky ControlAI | 21/11/2024 | 17/6/2026 | The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.1) | 0.38% | — | Embed Videos AND Respect PrivacyAI | 11/10/2024 | 17/6/2026 | The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Alta (8.8) | 0.21% | — | Kevinweber Lazy Load FOR Videos | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevin Weber Lazy Load for Videos plugin <= 2.18.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Gingertech External Videos | 14/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <= 2.0.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Digitalinspiration Google XML Sitemap FOR Videos | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. | |
| Modificada | Alta (7) | 0.35% | — | Getvideostream Videostream | 17/5/2023 | 17/6/2026 | Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours. | |
| Modificada | Crítica (9.3) | 1.4% | — | Videoserver Project Videoserver | 11/7/2022 | 17/6/2026 | The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.5) | 11% | — | Commoninja Videos Sync PDF | 25/4/2022 | 17/6/2026 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues | |
| Modificada | Alta (8.8) | 1.0% | — | Meomundo Related Youtube Videos | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (5.4) | 0.64% | — | Cisco Videoscape Anyres Live | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of… | |
| Modificada | Crítica (9.8) | 2.7% | — | Allvideos Reloaded Project Allvideos Reloaded | 17/2/2018 | 17/6/2026 | SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. |