Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.56% | — | Johnkerl MillerAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Miller christine-miller allows PHP Local File Inclusion.This issue affects Miller: from n/a through <= 1.3.3. | |
| Aplazada | Alta (7.1) | 0.15% | — | David Miller Revision DietAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in David Miller Revision Diet revision-diet allows Stored XSS.This issue affects Revision Diet: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.9) | 0.21% | — | David Miller Wp-ogpAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Miller WP-OGP wp-ogp allows Stored XSS.This issue affects WP-OGP: from n/a through <= 1.0.5. | |
| Aplazada | Media (4.3) | 0.39% | — | Matt Miller Send Emails With MandrillAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Matt Miller Send Emails with Mandrill send-emails-with-mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through <= 1.4.1. | |
| Modificada | Media (4.3) | 0.23% | — | Davidjmiller Similarity | 14/6/2024 | 17/6/2026 | The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Modificada | Media (4.3) | 0.20% | — | Davidjmiller Similarity | 14/6/2024 | 17/6/2026 | The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Millermedia Mandrill | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33. | |
| Modificada | Media (5.4) | 0.40% | — | Davidjmiller Voting Record | 16/1/2024 | 17/6/2026 | The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks | |
| Modificada | Media (5.4) | 0.21% | — | Davidjmiller Voting Record | 16/1/2024 | 17/6/2026 | The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Modificada | Alta (8.6) | 0.43% | — | Johnkerl Miller | 2/9/2020 | 17/6/2026 | In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be… | |
| Modificada | Alta (7) | 0.34% | — | Todd Miller Sudo | 14/4/2017 | 17/6/2026 | sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function. | |
| Modificada | Media (6.6) | 0.34% | — | Apple MAC OS XTodd Miller Sudo | 11/3/2014 | 17/6/2026 | Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended command restrictions via a crafted environment variable. | |
| Modificada | Media (4.4) | 0.36% | — | Apple MAC OS XTodd Miller Sudo | 8/4/2013 | 16/6/2026 | sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session without a controlling terminal device and… | |
| Modificada | Media (4.4) | 0.37% | — | Todd Miller SudoApple MAC OS X | 8/4/2013 | 16/6/2026 | sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors… | |
| Modificada | Media (4.4) | 0.37% | — | Apple MAC OS XTodd Miller Sudo | 8/4/2013 | 16/6/2026 | sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting to the standard input, output, and… | |
| Modificada | Media (6.9) | 3.2% | — | Todd Miller SudoApple MAC OS X | 5/3/2013 | 16/6/2026 | sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch. | |
| Modificada | Media (5.6) | 0.43% | — | Todd Miller SudoRedhat Enterprise Linux | 8/8/2012 | 16/6/2026 | A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file. | |
| Modificada | Alta (7.2) | 0.40% | — | Todd Miller Sudo | 18/5/2012 | 16/6/2026 | sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address. | |
| Modificada | Alta (7.2) | 2.9% | — | Todd Miller Sudo | 1/2/2012 | 16/6/2026 | Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo. | |
| Modificada | Media (6.9) | 0.33% | — | Todd Miller Sudo | 20/1/2011 | 16/6/2026 | A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a… | |
| Modificada | Media (4.4) | 0.50% | — | Todd Miller Sudo | 18/1/2011 | 16/6/2026 | check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command. | |
| Modificada | Media (6.2) | 0.36% | — | Todd Miller Sudo | 10/9/2010 | 16/6/2026 | Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence. | |
| Modificada | Media (6.2) | 0.46% | — | Todd Miller Sudo | 7/6/2010 | 16/6/2026 | The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable. | |
| Modificada | Media (6.9) | 0.40% | — | Todd Miller Sudo | 16/4/2010 | 16/6/2026 | The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable,… | |
| Modificada | Media (4.4) | 0.46% | — | Todd Miller Sudo | 25/2/2010 | 16/6/2026 | sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command. |