Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.60%—CustomsoundsAI4/8/20269/9/2026
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
ModificadaCrítica (9.8)0.80%—Peaksel Animal Sounds AND Ringtones31/3/202624/7/2026
An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AplazadaAlta (7.1)0.18%—Digitalzoomstudio ZoomsoundsAI31/12/202523/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS.This issue affects ZoomSounds: from n/a through 6.91.
AplazadaMedia (6.4)0.22%—SoundslidesAI27/11/202517/6/2026
The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaAlta (7.1)0.24%—Sound Strategies Soundst SEO SearchAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sound Strategies SoundSt SEO Search soundst-seo-search allows Reflected XSS.This issue affects SoundSt SEO Search: from n/a through <= 1.2.3.
AplazadaMedia (6.4)0.22%—WP SoundsystemAI26/6/202517/6/2026
The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.1)0.44%—Digitalzoomstudio Zoomsounds25/6/202517/6/2026
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.
ModificadaCrítica (9.8)0.51%—Digitalzoomstudio Zoomsounds23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91.
AnalizadaAlta (7.5)0.40%—Digitalzoomstudio Zoomsounds8/4/202517/6/2026
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain…
AnalizadaMedia (5.4)0.22%—Digitalzoomstudio Zoomsounds5/4/202517/6/2026
The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions…
AnalizadaAlta (8.1)0.35%—Digitalzoomstudio Zoomsounds5/4/202517/6/2026
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for…
AplazadaAlta (8.8)0.77%—SOJ SoundslidesAI29/3/202517/6/2026
The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload…
AnalizadaCrítica (9.8)0.64%—Digitalzoomstudio Zoomsounds5/3/202517/6/2026
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
AplazadaMedia (6.5)0.21%—Goldsounds VR ViewsAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goldsounds VR Views vr-views allows Stored XSS.This issue affects VR Views: from n/a through <= 1.5.1.
ModificadaCrítica (9.8)5.4%—Digitalzoomstudio Zoomsounds16/10/202417/6/2026
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code…
ModificadaMedia (6.1)0.34%—Asustor ADMAsustor LooksgoodAsustor Soundsgood17/5/202317/6/2026
A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by the browser and used with that application. Affected products and…
ModificadaCrítica (9.8)0.63%—Soundslike Project Soundslike18/1/202317/6/2026
A vulnerability was found in ridhoq soundslike. It has been classified as critical. Affected is the function get_song_relations of the file app/api/songs.py. The manipulation leads to sql injection. The patch is identified as 90bb4fb667d9253d497b619b9adaac83bf0ce0f8. It is recommended to apply a patch to fix this…
ModificadaAlta (7.5)66%—Digitalzoomstudio Zoomsounds31/8/202117/6/2026
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.
ModificadaAlta (8.8)1.0%—Jenkins Sounds15/1/202017/6/2026
A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.
ModificadaAlta (8.8)1.2%—Jenkins Sounds15/1/202017/6/2026
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.
ModificadaCrítica (9.8)4.0%—Digitalzoomstudio Zoomsounds10/10/201917/6/2026
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
ModificadaMedia (5.4)0.90%—Asustor Soundsgood22/5/201817/6/2026
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.
ModificadaAlta (7.5)55%—Csounds Csound17/2/201416/6/2026
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.
ModificadaAlta (9.3)6.6%—Csounds Csound4/2/201416/6/2026
Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.
ModificadaAlta (9.3)6.7%—Csounds Csound4/2/201416/6/2026
Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.