Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
438 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.1) | 0.16% | — | Codexonics Prime MoverAI | 1/10/2026 | 1/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory… | |
| Recibida | Alta (7) | 0.34% | — | Codexonics Prime MoverAI | 1/10/2026 | 1/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation… | |
| Recibida | Alta (8.6) | 0.59% | — | Codexonics Prime MoverAI | 1/10/2026 | 1/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Nasa Fprime-gdsAI | 10/8/2026 | 28/8/2026 | Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nasa FprimeAI | 3/8/2026 | 9/9/2026 | An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nasa FprimeAI | 3/8/2026 | 31/8/2026 | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters. | |
| Aplazada | Media (5.3) | 0.54% | — | Primefaces PrimereactAI | 13/7/2026 | 27/8/2026 | A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the file components/lib/utils/ObjectUtils.js of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The… | |
| Aplazada | Alta (7.2) | 0.43% | — | EventprimeAI | 9/7/2026 | 9/7/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.52% | — | EventprimeAI | 25/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Pressprimer QuizAI | 18/6/2026 | 18/6/2026 | The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Alta (8.1) | 0.44% | — | EventprimeAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. | |
| Aplazada | Alta (7.1) | 0.38% | — | EventprimeAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions. | |
| Aplazada | Alta (7.1) | 0.29% | — | EventprimeAI | 15/6/2026 | 17/6/2026 | Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions. | |
| Aplazada | Media (6.4) | 0.43% | — | Prime Elementor AddonsAI | 9/6/2026 | 23/7/2026 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.35% | — | EventprimeAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0. | |
| Aplazada | Media (6.2) | 0.16% | — | Protocol Go-ipld-primeAI | 27/5/2026 | 17/6/2026 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.23.0, the DAG-CBOR and DAG-JSON decoders recurse on each nested map or list without a depth… | |
| Analizada | Media (4.3) | 0.21% | — | Cisco Prime Infrastructure | 6/5/2026 | 29/6/2026 | A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this… | |
| Pendiente de análisis | Alta (8.6) | 0.16% | — | Mersenne Prime95AI | 29/4/2026 | 17/6/2026 | Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and… | |
| Aplazada | Media (6.9) | 0.14% | — | Mersenne Prime95AI | 26/4/2026 | 17/6/2026 | Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional proxy password field. Attackers can trigger a denial of service by entering a 6000-byte payload into the proxy password… | |
| Analizada | Crítica (9.8) | 0.77% | — | Nasa Fprime | 22/4/2026 | 17/6/2026 | F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An attacker-crafted DataPacket with byteOffset=0xFFFFFF9C and… | |
| Aplazada | Media (6.4) | 0.35% | — | Bdthemes Prime SliderAI | 8/4/2026 | 25/7/2026 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()`… | |
| Analizada | Media (6.2) | 0.16% | — | Protocol Go-ipld-prime | 7/4/2026 | 17/6/2026 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.22.0, the DAG-CBOR decoder uses collection sizes declared in CBOR headers as Go preallocation… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Metagauss EventprimeAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0. | |
| Aplazada | Alta (7.5) | 0.31% | — | Metagauss EventprimeAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.6.0. | |
| Aplazada | Alta (7.5) | 0.21% | — | Metagauss EventprimeAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3. |