Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.26% | — | 9routerAIOpen-sse TranslatorAI | 10/7/2026 | 13/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access to the LLM proxy can use a vision-capable… | |
| Aplazada | Crítica (9.2) | 0.62% | — | Manga-image-translatorAI | 29/5/2026 | 21/7/2026 | manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request bodies using… | |
| Aplazada | Media (6.5) | 0.46% | — | Smartcat Translator FOR WpmlAI | 15/5/2026 | 17/6/2026 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and including, 3.1.77. This makes it possible for unauthenticated attackers to overwrite the plugin's Smartcat API… | |
| Analizada | Crítica (9.8) | 0.83% | — | Deftpdf Document Translator | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Baja (2.1) | 0.44% | — | Zyddnys Manga-image-translatorAI | 11/3/2026 | 17/6/2026 | A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. The affected element is the function to_pil_image of the file manga-image-translator-main/server/request_extraction.py of the component Translate Endpoints. This manipulation causes server-side request forgery. It is possible to initiate… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Manga Image TranslatorAI | 11/2/2026 | 14/7/2026 | manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled request bodies using pickle.loads() without… | |
| Aplazada | Crítica (9.2) | 0.26% | — | Siemens ComosAISiemens JT Bi-directional Translator FOR StepAISiemens NXAISiemens Simcenter 3DAI+5 | 9/12/2025 | 30/9/2026 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as… | |
| Aplazada | Alta (7.3) | 0.20% | — | Siemens PS Iges Parasolid Translator ComponentAISiemens Simcenter FemapAISiemens Solid EdgeAI | 17/11/2025 | 17/6/2026 | A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This… | |
| Aplazada | Media (6.5) | 0.31% | — | Smartcat Translator FOR WpmlAI | 11/9/2025 | 17/6/2026 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 3.1.72 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.14% | — | Hossin Asaadi WP Permalink TranslatorAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hossin Asaadi WP Permalink Translator wp-permalink-translator allows Stored XSS.This issue affects WP Permalink Translator: from n/a through <= 1.7.6. | |
| Aplazada | Media (5.4) | 0.16% | — | Pozzad Global TranslatorAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pozzad Global Translator global-translator allows Cross Site Request Forgery.This issue affects Global Translator: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.9) | 0.26% | — | Pozzad Global TranslatorAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pozzad Global Translator global-translator allows Stored XSS.This issue affects Global Translator: from n/a through <= 2.0.2. | |
| Analizada | Media (4.8) | 0.31% | — | Prisna Google Website Translator | 15/5/2025 | 17/6/2026 | The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Prisna Google Website Translator | 15/5/2025 | 17/6/2026 | The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.16% | — | Kornelly TranslatorAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator translator allows Stored XSS.This issue affects Translator: from n/a through <= 0.3. | |
| Aplazada | Media (6.9) | 0.49% | — | MousetooltiptranslatorAI | 3/3/2025 | 17/6/2026 | The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses the URL parameter from the current URL as the file to download and display to the extension user. Because pdf.mjs is… | |
| Aplazada | Media (4.3) | 0.23% | — | Aitool Aikct Engine ChatbotAIOpenai ChatgptAIGoogle GeminiAIOpenai Gpt-4oAI+1 | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aitool AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot ai-seo-translator allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot: from n/a through <= 1.6.2. | |
| Aplazada | Media (5.3) | 0.54% | — | Gtranslate Google Language TranslatorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in edo888 Google Language Translator google-language-translator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Language Translator: from n/a through <= 6.0.19. | |
| Analizada | Media (5.4) | 0.51% | — | Gtranslate Google Language Translator | 16/10/2024 | 17/6/2026 | The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Alta (7.2) | 1.00% | — | Prisna Google Website Translator | 25/9/2024 | 17/6/2026 | The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (4.4) | 0.27% | — | Automatic Translator With Google TranslateAI | 22/5/2024 | 17/6/2026 | The Automatic Translator with Google Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom font setting in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.3) | 0.39% | — | Siemens Ps/iges Parasolid TranslatorSiemens Simcenter Femap | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21578) | |
| Analizada | Alta (7.3) | 0.39% | — | Siemens Ps/iges Parasolid TranslatorSiemens Simcenter Femap | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21577) | |
| Analizada | Alta (7.3) | 0.39% | — | Siemens Ps/iges Parasolid TranslatorSiemens Simcenter Femap | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21575) | |
| Analizada | Alta (7.3) | 0.39% | — | Siemens Ps/iges Parasolid TranslatorSiemens Simcenter Femap | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21573) |