Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

438 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.1)0.16%—Codexonics Prime MoverAI1/10/20261/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory…
RecibidaAlta (7)0.34%—Codexonics Prime MoverAI1/10/20261/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation…
RecibidaAlta (8.6)0.59%—Codexonics Prime MoverAI1/10/20261/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by…
AplazadaCrítica (9.8)1.3%—Nasa Fprime-gdsAI10/8/202628/8/2026
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.
AplazadaAlta (7.5)0.49%—Nasa FprimeAI3/8/20269/9/2026
An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.
AplazadaAlta (7.5)0.49%—Nasa FprimeAI3/8/202631/8/2026
The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.
AplazadaMedia (5.3)0.54%—Primefaces PrimereactAI13/7/202627/8/2026
A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the file components/lib/utils/ObjectUtils.js of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The…
AplazadaAlta (7.2)0.43%—EventprimeAI9/7/20269/7/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (8.8)0.52%—EventprimeAI25/6/202626/6/2026
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
AplazadaMedia (4.3)0.25%—Pressprimer QuizAI18/6/202618/6/2026
The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated…
AplazadaAlta (8.1)0.44%—EventprimeAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
AplazadaAlta (7.1)0.38%—EventprimeAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.
AplazadaAlta (7.1)0.29%—EventprimeAI15/6/202617/6/2026
Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.
AplazadaMedia (6.4)0.43%—Prime Elementor AddonsAI9/6/202623/7/2026
The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.5)0.35%—EventprimeAI2/6/202622/7/2026
Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.
AplazadaMedia (6.2)0.16%—Protocol Go-ipld-primeAI27/5/202617/6/2026
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.23.0, the DAG-CBOR and DAG-JSON decoders recurse on each nested map or list without a depth…
AnalizadaMedia (4.3)0.21%—Cisco Prime Infrastructure6/5/202629/6/2026
A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&nbsp;authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this…
Pendiente de análisisAlta (8.6)0.16%—Mersenne Prime95AI29/4/202617/6/2026
Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and…
AplazadaMedia (6.9)0.14%—Mersenne Prime95AI26/4/202617/6/2026
Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional proxy password field. Attackers can trigger a denial of service by entering a 6000-byte payload into the proxy password…
AnalizadaCrítica (9.8)0.77%—Nasa Fprime22/4/202617/6/2026
F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An attacker-crafted DataPacket with byteOffset=0xFFFFFF9C and…
AplazadaMedia (6.4)0.35%—Bdthemes Prime SliderAI8/4/202625/7/2026
The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()`…
AnalizadaMedia (6.2)0.16%—Protocol Go-ipld-prime7/4/202617/6/2026
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.22.0, the DAG-CBOR decoder uses collection sizes declared in CBOR headers as Go preallocation…
AplazadaCrítica (9.8)0.51%—Metagauss EventprimeAI25/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.
AplazadaAlta (7.5)0.31%—Metagauss EventprimeAI25/3/202617/6/2026
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.6.0.
AplazadaAlta (7.5)0.21%—Metagauss EventprimeAI19/3/202617/6/2026
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3.