Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2807▲ 74 respecto a la semana anterior
Críticas / altas1475▲ 313 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.29% | — | FlameAI | 25/9/2026 | 30/9/2026 | Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password… | |
| Aplazada | Alta (8.3) | 0.29% | — | FlameAI | 25/9/2026 | 30/9/2026 | Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or… | |
| Aplazada | Media (6.9) | 0.34% | — | FlameAI | 25/9/2026 | 30/9/2026 | Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending a single unauthenticated request to… | |
| Aplazada | Media (5.1) | 0.14% | — | FlameshotAI | 15/7/2026 | 15/7/2026 | Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause… | |
| Aplazada | Media (5.3) | 0.23% | — | Flamescorpion Auto Affiliate LinksAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3. | |
| Aplazada | Alta (7.2) | 0.51% | — | Flamescorpion Auto Affiliate LinksAI | 8/5/2026 | 17/6/2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(),… | |
| Aplazada | Alta (8.5) | 0.41% | — | Flame II Hspa USB ModemAI | 13/1/2026 | 17/6/2026 | Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges. | |
| Analizada | Media (5.4) | 0.33% | — | Flamescorpion Auto Affiliate Links | 15/5/2025 | 17/6/2026 | The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Aplazada | Media (6.5) | 0.66% | — | Flamescorpion Auto Affiliate LinksAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5. | |
| Aplazada | Alta (7.6) | 0.52% | — | Flamescorpion Auto Affiliate LinksAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1. | |
| Modificada | Media (4.3) | 0.53% | — | Flamescorpion Auto Affiliate Links | 13/3/2024 | 17/6/2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to… | |
| Modificada | Media (6.1) | 0.21% | — | Flamescorpion Auto Affiliate Links | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4. | |
| Modificada | Alta (8.8) | 0.26% | — | Flamescorpion Auto Affiliate Links | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Flamescorpion Auto Affiliate Links | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions. | |
| Modificada | Media (6.1) | 0.49% | — | Flame.js Project Flame.js | 5/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in flame.js. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The… | |
| Modificada | Crítica (9.8) | 1.1% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | |
| Modificada | Crítica (9.8) | 0.99% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | |
| Modificada | Crítica (9.8) | 5.0% | — | Flamecms Project Flamecms | 14/9/2019 | 17/6/2026 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | |
| Modificada | Media (5.4) | 0.27% | — | Intellectualflame Brightest LED Flashlight | 9/9/2014 | 17/6/2026 | The Brightest LED Flashlight (aka com.intellectualflame.ledflashlight.washer) application 1.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.31% | — | Dann Frazier Flamethrower | 18/11/2008 | 16/6/2026 | flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file. |