Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.29% | — | Flippercode WP MapsAI | 31/7/2026 | 12/8/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6. | |
| Aplazada | Alta (8.4) | 0.19% | — | Flipper Devices Flipperzero FirmwareAI | 1/5/2026 | 17/6/2026 | flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function. | |
| Aplazada | Alta (7.5) | 0.70% | — | Flippercode WP MapsAI | 11/3/2026 | 17/6/2026 | The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in backticks as column names,… | |
| Aplazada | Media (6.6) | 0.37% | — | Flippercode WP MapsAI | 9/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6. | |
| Aplazada | Media (6.4) | 0.22% | — | Wordpress Content FlipperAI | 13/11/2025 | 17/6/2026 | The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortcode attribute of the 'flipper_front' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | Flippercode Advanced Google MapsAI | 6/11/2025 | 30/9/2026 | Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Google Maps: from n/a through <= 5.8.4. | |
| Analizada | Media (5.3) | 0.29% | — | Opentext Flipper | 21/10/2025 | 17/6/2026 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2. | |
| Analizada | Baja (1) | 0.36% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | SQL Injection vulnerability in opentext Flipper allows SQL Injection. The vulnerability could allow a low privilege user to interact with the database in unintended ways and extract data by interacting with the HQL processor. This issue affects Flipper: 3.1.2. | |
| Analizada | Media (5.3) | 0.39% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2. | |
| Analizada | Baja (2.3) | 0.28% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low-privilege user to elevate privileges within the application. This issue affects Flipper: 3.1.2. | |
| Analizada | Media (5.3) | 0.29% | — | Opentext Flipper | 20/10/2025 | 17/6/2026 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local file path and then download the specified file from the system by requesting the stored document ID. This issue affects Flipper: 3.1.2. | |
| Analizada | Baja (1) | 0.26% | — | Opentext Flipper | 20/10/2025 | 1/10/2026 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow a low privilege user to interact with the backend API without sufficient privileges. This issue affects Flipper: 3.1.2. | |
| Modificada | Media (4.3) | 0.38% | — | Flippercode Wp-security-questions | 1/7/2023 | 17/6/2026 | The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request… | |
| Modificada | Media (5.5) | 0.35% | — | Flipperzero Flipper Zero Firmware | 29/9/2022 | 17/6/2026 | A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file. | |
| Modificada | Media (5.4) | 0.81% | — | Flippercode WP Google MAP | 14/5/2018 | 17/6/2026 | Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Invision Power Services Invision Power BoardPhpbbSebflipper Multi-forums Module | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters. | |
| Modificada | Alta (7.5) | 4.3% | — | Flipper Poll | 21/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. |