Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.23% | — | Horiyuki Image-switcherAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in horiyuki Image Switcher image-switcher allows Stored XSS.This issue affects Image Switcher: from n/a through <= 0.1.1. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Takayukii ACF Images Search AND InsertAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through <= 1.1.4. | |
| Modificada | Media (4.3) | 0.21% | — | Wpmoose Yuki | 28/2/2024 | 17/6/2026 | The Yuki theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 1.3.14. This is due to missing or incorrect nonce validation on the reset_customizer_options() function. This makes it possible for unauthenticated attackers to reset the themes settings via a forged request… | |
| Modificada | Media (4.3) | 0.34% | — | Wpmoose Yuki | 28/2/2024 | 17/6/2026 | The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_customizer_options() function in all versions up to, and including, 1.3.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset the theme's… | |
| Modificada | Media (5.4) | 0.33% | — | Takayukimiyauchi Oembed Gist | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takayuki Miyauchi oEmbed Gist allows Stored XSS.This issue affects oEmbed Gist: from n/a through 4.9.1. | |
| Modificada | Media (5.4) | 0.43% | — | Yukimichi Simple Sort&search | 16/1/2024 | 17/6/2026 | The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor | |
| Modificada | Alta (7.5) | 1.1% | — | Hyuki Yukiwiki | 15/11/2018 | 17/6/2026 | YukiWiki 2.1.3 and earlier does not process a particular request properly that may allow consumption of large amounts of CPU and memory resources and may result in causing a denial of service condition. | |
| Modificada | Media (6.1) | 0.79% | — | Hyuki Yukiwiki | 15/11/2018 | 17/6/2026 | Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.64% | — | Intercom WEB Kyukincho | 28/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 1.1% | — | Intercom WEB Kyukincho | 28/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Hiroyuki Oyama Dbd\ | 4/11/2011 | 16/6/2026 | SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 3.8% | — | Yukihiro Matsumoto Ruby | 6/12/2006 | 16/6/2026 | The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467. | |
| Modificada | Media (5) | 4.5% | — | Yukihiro Matsumoto Ruby | 27/10/2006 | 16/6/2026 | The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent… | |
| Modificada | Media (6.4) | 5.8% | — | Yukihiro Matsumoto Ruby | 21/7/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations". | |
| Modificada | Media (5) | 10% | — | Yukihiro Matsumoto Ruby | 20/4/2006 | 16/6/2026 | The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data. | |
| Modificada | Alta (7.5) | 3.3% | — | Yukihiro Matsumoto Ruby | 7/10/2005 | 16/6/2026 | Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin). | |
| Modificada | Alta (7.5) | 6.6% | — | Yukihiro Matsumoto Ruby | 20/6/2005 | 16/6/2026 | The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5) | 1.9% | — | Yukihiro Matsumoto RubyGentoo LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+1 | 1/3/2005 | 16/6/2026 | The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request. | |
| Modificada | Baja (2.1) | 0.36% | — | Yukihiro Matsumoto Ruby | 20/10/2004 | 16/6/2026 | The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions. |