Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.19%—Remove Yellow BgboxAI20/5/202623/7/2026
The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_api_settings' page. This makes it possible for unauthenticated attackers to reset the plugin's stored settings by…
AplazadaAlta (7.1)0.22%—Ta2g TantyyellowAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow allows Reflected XSS.This issue affects Tantyyellow: from n/a through 1.0.0.5.
AnalizadaMedia (6.1)0.35%—Waspthemes Yellowpencil29/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1.
ModificadaMedia (6.1)1.0%—Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaMedia (5.4)0.47%—Yellowyard Yellow Yard Searchbar16/8/202317/6/2026
The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.49%—Yellowyard Yellow Yard Searchbar8/2/202317/6/2026
The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.90%—Idera Yellowfin Business Intelligence14/9/202217/6/2026
Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.
ModificadaCrítica (9)1.5%—Yellowfinbi Business Intelligence14/9/202217/6/2026
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
ModificadaMedia (6.1)1.4%—Yellowpencil Visual CSS Style Editor1/2/202217/6/2026
The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
ModificadaAlta (7.5)3.1%—Yellowfinbi Yellowfin14/10/202117/6/2026
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".
ModificadaAlta (7.5)3.2%—Yellowfinbi Yellowfin14/10/202117/6/2026
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".
ModificadaMedia (5.4)1.5%—Yellowfinbi Yellowfin14/10/202117/6/2026
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".
ModificadaAlta (8.8)4.3%—Dimo-crm Yellowbox CRM21/1/202017/6/2026
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.
ModificadaAlta (7.5)1.4%—Dimo-crm Yellowbox CRM21/1/202017/6/2026
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
ModificadaMedia (6.5)1.1%—Dimo-crm Yellowbox CRM21/1/202017/6/2026
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
ModificadaAlta (8.8)1.1%—Dimo-crm Yellowbox CRM21/1/202017/6/2026
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.
ModificadaMedia (5.4)0.65%—BMC Remedy Smart ReportingYellowfinbi Yellowfin BI26/7/201917/6/2026
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web…
ModificadaAlta (8.8)1.9%—Yellowpencil Visual CSS Style Editor13/5/201917/6/2026
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
ModificadaMedia (6.5)0.47%—Datenstrom Yellow5/5/201817/6/2026
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
ModificadaMedia (5.4)0.64%—Datenstrom Yellow4/5/201817/6/2026
A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS
ModificadaMedia (5.4)0.27%—Avantar White & Yellow Pages10/9/201417/6/2026
The White & Yellow Pages (aka com.avantar.wny) application 5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.30%—Yellowbook Yellow Pages Local Search9/9/201417/6/2026
The Yellow Pages Local Search (aka com.yellowbook.android2) application 11.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.8%—Yellowswordfish Simple Forum24/8/200916/6/2026
SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.
ModificadaAlta (7.5)1.3%—Phpyellowtm LitePhpyellowtm PRO5/12/200516/6/2026
Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.