Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Remove Yellow BgboxAI | 20/5/2026 | 23/7/2026 | The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_api_settings' page. This makes it possible for unauthenticated attackers to reset the plugin's stored settings by… | |
| Aplazada | Alta (7.1) | 0.22% | — | Ta2g TantyyellowAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow allows Reflected XSS.This issue affects Tantyyellow: from n/a through 1.0.0.5. | |
| Analizada | Media (6.1) | 0.35% | — | Waspthemes Yellowpencil | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through 7.6.1. | |
| Modificada | Media (6.1) | 1.0% | — | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (5.4) | 0.47% | — | Yellowyard Yellow Yard Searchbar | 16/8/2023 | 17/6/2026 | The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.49% | — | Yellowyard Yellow Yard Searchbar | 8/2/2023 | 17/6/2026 | The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.90% | — | Idera Yellowfin Business Intelligence | 14/9/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI. | |
| Modificada | Crítica (9) | 1.5% | — | Yellowfinbi Business Intelligence | 14/9/2022 | 17/6/2026 | Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI. | |
| Modificada | Media (6.1) | 1.4% | — | Yellowpencil Visual CSS Style Editor | 1/2/2022 | 17/6/2026 | The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.5) | 3.1% | — | Yellowfinbi Yellowfin | 14/10/2021 | 17/6/2026 | In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4". | |
| Modificada | Alta (7.5) | 3.2% | — | Yellowfinbi Yellowfin | 14/10/2021 | 17/6/2026 | In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4". | |
| Modificada | Media (5.4) | 1.5% | — | Yellowfinbi Yellowfin | 14/10/2021 | 17/6/2026 | In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4". | |
| Modificada | Alta (8.8) | 4.3% | — | Dimo-crm Yellowbox CRM | 21/1/2020 | 17/6/2026 | An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges. | |
| Modificada | Alta (7.5) | 1.4% | — | Dimo-crm Yellowbox CRM | 21/1/2020 | 17/6/2026 | In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server. | |
| Modificada | Media (6.5) | 1.1% | — | Dimo-crm Yellowbox CRM | 21/1/2020 | 17/6/2026 | Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem. | |
| Modificada | Alta (8.8) | 1.1% | — | Dimo-crm Yellowbox CRM | 21/1/2020 | 17/6/2026 | Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers. | |
| Modificada | Media (5.4) | 0.65% | — | BMC Remedy Smart ReportingYellowfinbi Yellowfin BI | 26/7/2019 | 17/6/2026 | Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web… | |
| Modificada | Alta (8.8) | 1.9% | — | Yellowpencil Visual CSS Style Editor | 13/5/2019 | 17/6/2026 | The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access. | |
| Modificada | Media (6.5) | 0.47% | — | Datenstrom Yellow | 5/5/2018 | 17/6/2026 | The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles. | |
| Modificada | Media (5.4) | 0.64% | — | Datenstrom Yellow | 4/5/2018 | 17/6/2026 | A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users is supposed to have parserSafeMode=1 in system/config/config.ini to prevent XSS | |
| Modificada | Media (5.4) | 0.27% | — | Avantar White & Yellow Pages | 10/9/2014 | 17/6/2026 | The White & Yellow Pages (aka com.avantar.wny) application 5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Yellowbook Yellow Pages Local Search | 9/9/2014 | 17/6/2026 | The Yellow Pages Local Search (aka com.yellowbook.android2) application 11.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.8% | — | Yellowswordfish Simple Forum | 24/8/2009 | 16/6/2026 | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpyellowtm LitePhpyellowtm PRO | 5/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php. |