Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2807▲ 74 respecto a la semana anterior
Críticas / altas1475▲ 313 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.29%—FlameAI25/9/202630/9/2026
Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password…
AplazadaAlta (8.3)0.29%—FlameAI25/9/202630/9/2026
Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or…
AplazadaMedia (6.9)0.34%—FlameAI25/9/202630/9/2026
Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to…
AplazadaMedia (5.1)0.14%—FlameshotAI15/7/202615/7/2026
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause…
AplazadaMedia (5.3)0.23%—Flamescorpion Auto Affiliate LinksAI25/5/202624/7/2026
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.
AplazadaAlta (7.2)0.51%—Flamescorpion Auto Affiliate LinksAI8/5/202617/6/2026
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(),…
AplazadaAlta (8.5)0.41%—Flame II Hspa USB ModemAI13/1/202617/6/2026
Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.
AnalizadaMedia (5.4)0.33%—Flamescorpion Auto Affiliate Links15/5/202517/6/2026
The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
AplazadaMedia (6.5)0.66%—Flamescorpion Auto Affiliate LinksAI13/12/202417/6/2026
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.
AplazadaAlta (7.6)0.52%—Flamescorpion Auto Affiliate LinksAI6/5/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.
ModificadaMedia (4.3)0.53%—Flamescorpion Auto Affiliate Links13/3/202417/6/2026
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to…
ModificadaMedia (6.1)0.21%—Flamescorpion Auto Affiliate Links13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4.
ModificadaAlta (8.8)0.26%—Flamescorpion Auto Affiliate Links20/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions.
ModificadaAlta (8.8)0.25%—Flamescorpion Auto Affiliate Links13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.
ModificadaMedia (6.1)0.49%—Flame.js Project Flame.js5/3/202317/6/2026
A vulnerability classified as problematic has been found in flame.js. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The…
ModificadaCrítica (9.8)1.1%—Flamecms Project Flamecms30/9/202117/6/2026
FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
ModificadaCrítica (9.8)0.99%—Flamecms Project Flamecms30/9/202117/6/2026
FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
ModificadaCrítica (9.8)5.0%—Flamecms Project Flamecms14/9/201917/6/2026
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
ModificadaMedia (5.4)0.27%—Intellectualflame Brightest LED Flashlight9/9/201417/6/2026
The Brightest LED Flashlight (aka com.intellectualflame.ledflashlight.washer) application 1.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.9)0.31%—Dann Frazier Flamethrower18/11/200816/6/2026
flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file.