Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

575 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.24%—Wpdeveloper EmbedpressAI30/9/202630/9/2026
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
AplazadaMedia (6.8)0.24%—Wpdeveloper EmbedpressAI27/9/202628/9/2026
The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
AplazadaAlta (7.5)0.26%—Star-citizen EmbedvideoAI24/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute…
Pendiente de análisisBaja (2.9)0.10%—Mbed TLSAI24/9/202624/9/2026
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
AplazadaMedia (6.1)0.37%—Wpdeveloper EmbedpressAI18/9/202618/9/2026
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes…
AplazadaAlta (7.5)0.49%—Mediawiki EmbedvideoAI15/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON…
AplazadaAlta (8.6)0.48%—Mediawiki EmbedvideoAI15/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to…
AplazadaAlta (7.5)0.49%—Star-citizen EmbedvideoAI15/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown…
AplazadaMedia (5.3)0.27%—3D Flipbook PDF EmbedderAI15/9/202617/9/2026
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full…
Pendiente de análisisCrítica (9.1)0.54%—Eclipse Embedded CDTAIARM Cmsis-packAI14/9/202616/9/2026
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
Pendiente de análisisBaja (3.7)0.28%—Mbed TLSAI14/9/202622/9/2026
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
AplazadaMedia (6.9)0.58%—Embedded-graphicsAI13/9/202615/9/2026
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project…
AplazadaMedia (6.9)0.52%—Embedded-graphicsAI13/9/202616/9/2026
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through…
AplazadaAlta (8.8)0.51%—Youtube EmbedAI13/9/202614/9/2026
The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will…
AnalizadaCrítica (9.8)7.5%⚠ Explotación activaCheckpoint Gaia EmbeddedCheckpoint Gaia OS9/9/202623/9/2026
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
AplazadaMedia (5.3)0.30%—Wpdeveloper EmbedpressAI5/9/20268/9/2026
The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows…
AplazadaBaja (2.7)0.28%—Wpdeveloper EmbedpressAI5/9/20268/9/2026
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly…
AplazadaBaja (2.7)0.32%—Wpdeveloper EmbedpressAI5/9/20268/9/2026
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.
AplazadaCrítica (10)0.55%—Embed Html5 GameAI2/9/20263/9/2026
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
AplazadaMedia (5.3)0.19%—Bplugins Document EmbedderAI27/8/202628/8/2026
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.
Pendiente de análisisAlta (7.5)0.53%—Kaltura Html5libAIKaltura MwembedAI25/8/20263/9/2026
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the…
Pendiente de análisisCrítica (9.8)1.0%—Kaltura Html5libAIKaltura MwembedAI25/8/20263/9/2026
The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s…
AplazadaAlta (7.1)0.25%—TagembedAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
AplazadaMedia (6.4)0.55%—Lemmy-uiAIMarkdown-it-html5-embedAI19/8/20269/9/2026
Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a…
Pendiente de análisisBaja (2)0.36%—OpenvpnAIARM MbedtlsAI14/8/20261/9/2026
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field