Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.60% | — | CustomsoundsAI | 4/8/2026 | 9/9/2026 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory. | |
| Modificada | Crítica (9.8) | 0.80% | — | Peaksel Animal Sounds AND Ringtones | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Alta (7.1) | 0.18% | — | Digitalzoomstudio ZoomsoundsAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS.This issue affects ZoomSounds: from n/a through 6.91. | |
| Aplazada | Media (6.4) | 0.22% | — | SoundslidesAI | 27/11/2025 | 17/6/2026 | The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Alta (7.1) | 0.24% | — | Sound Strategies Soundst SEO SearchAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sound Strategies SoundSt SEO Search soundst-seo-search allows Reflected XSS.This issue affects SoundSt SEO Search: from n/a through <= 1.2.3. | |
| Aplazada | Media (6.4) | 0.22% | — | WP SoundsystemAI | 26/6/2025 | 17/6/2026 | The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.1) | 0.44% | — | Digitalzoomstudio Zoomsounds | 25/6/2025 | 17/6/2026 | The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server. | |
| Modificada | Crítica (9.8) | 0.51% | — | Digitalzoomstudio Zoomsounds | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91. | |
| Analizada | Alta (7.5) | 0.40% | — | Digitalzoomstudio Zoomsounds | 8/4/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Analizada | Media (5.4) | 0.22% | — | Digitalzoomstudio Zoomsounds | 5/4/2025 | 17/6/2026 | The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions… | |
| Analizada | Alta (8.1) | 0.35% | — | Digitalzoomstudio Zoomsounds | 5/4/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.77% | — | SOJ SoundslidesAI | 29/3/2025 | 17/6/2026 | The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload… | |
| Analizada | Crítica (9.8) | 0.64% | — | Digitalzoomstudio Zoomsounds | 5/3/2025 | 17/6/2026 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP… | |
| Aplazada | Media (6.5) | 0.21% | — | Goldsounds VR ViewsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goldsounds VR Views vr-views allows Stored XSS.This issue affects VR Views: from n/a through <= 1.5.1. | |
| Modificada | Crítica (9.8) | 5.4% | — | Digitalzoomstudio Zoomsounds | 16/10/2024 | 17/6/2026 | The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code… | |
| Modificada | Media (6.1) | 0.34% | — | Asustor ADMAsustor LooksgoodAsustor Soundsgood | 17/5/2023 | 17/6/2026 | A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by the browser and used with that application. Affected products and… | |
| Modificada | Crítica (9.8) | 0.63% | — | Soundslike Project Soundslike | 18/1/2023 | 17/6/2026 | A vulnerability was found in ridhoq soundslike. It has been classified as critical. Affected is the function get_song_relations of the file app/api/songs.py. The manipulation leads to sql injection. The patch is identified as 90bb4fb667d9253d497b619b9adaac83bf0ce0f8. It is recommended to apply a patch to fix this… | |
| Modificada | Alta (7.5) | 66% | — | Digitalzoomstudio Zoomsounds | 31/8/2021 | 17/6/2026 | The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter. | |
| Modificada | Alta (8.8) | 1.0% | — | Jenkins Sounds | 15/1/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins. | |
| Modificada | Alta (8.8) | 1.2% | — | Jenkins Sounds | 15/1/2020 | 17/6/2026 | Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins. | |
| Modificada | Crítica (9.8) | 4.0% | — | Digitalzoomstudio Zoomsounds | 10/10/2019 | 17/6/2026 | The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. | |
| Modificada | Media (5.4) | 0.90% | — | Asustor Soundsgood | 22/5/2018 | 17/6/2026 | A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter. | |
| Modificada | Alta (7.5) | 55% | — | Csounds Csound | 17/2/2014 | 16/6/2026 | Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c. | |
| Modificada | Alta (9.3) | 6.6% | — | Csounds Csound | 4/2/2014 | 16/6/2026 | Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Alta (9.3) | 6.7% | — | Csounds Csound | 4/2/2014 | 16/6/2026 | Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow. |