Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.64% | — | WIN MEN International Travel Agency Management SystemAI | 11/8/2026 | 26/8/2026 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Media (4.3) | 0.17% | — | Mooveagency Gdpr Cookie ComplianceAI | 5/8/2026 | 26/8/2026 | The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link. | |
| Aplazada | Alta (8.1) | 0.35% | — | Line AgencyAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Select-themes Borgholm Marketing Agency ThemeAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Travel AgencyAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Agency: from n/a through <= 1.5.5. | |
| Aplazada | Alta (8.1) | 0.49% | — | Axiomthemes AU Pair AgencyAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through <= 1.2.2. | |
| Analizada | Baja (2.1) | 0.29% | — | Mayurik GAS Agency Management System | 6/2/2026 | 17/6/2026 | A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be… | |
| Analizada | Baja (2.1) | 0.36% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be launched remotely.… | |
| Analizada | Baja (2) | 0.38% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Baja (2.1) | 0.38% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to… | |
| Aplazada | Media (6.4) | 0.18% | — | Angel Fashion Model AgencyAI | 13/11/2025 | 7/10/2026 | The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting the profile media uploader in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.20% | — | Agency Dominion INC Fusion Page Builder Extension GalleryAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery fusion-extension-gallery allows Stored XSS.This issue affects Fusion Page Builder : Extension – Gallery: from n/a through <= 1.7.6. | |
| Analizada | Media (4.3) | 0.14% | — | Themebon Digital Marketing AND Agency Templates Addons FOR Elementor | 13/6/2025 | 17/6/2026 | The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Themeton THE Fashion - Model Agency ONE Page Beauty ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This issue affects The Fashion - Model Agency One Page Beauty Theme: from n/a through <= 1.4.4. | |
| Modificada | Media (5.3) | 0.36% | — | Mooveagency User Activity Tracking AND LOG | 15/5/2025 | 17/6/2026 | This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. | |
| Aplazada | Media (5.3) | 0.36% | — | Inspry Agency-toolkitAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Agency Toolkit: from n/a through <= 1.0.24. | |
| Aplazada | Media (6.5) | 0.26% | — | Agency Dominion INC FusionAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion allows DOM-Based XSS.This issue affects Fusion: from n/a through <= 1.6.4. | |
| Analizada | Baja (3.5) | 0.26% | — | Mooveagency Gdpr Cookie Compliance | 16/3/2025 | 17/6/2026 | The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.26% | — | Mooveagency Gdpr Cookie Compliance | 16/3/2025 | 17/6/2026 | The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.22% | — | Mooveagency Gdpr Cookie Compliance | 16/3/2025 | 17/6/2026 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.26% | — | Mooveagency Gdpr Cookie Compliance | 16/3/2025 | 17/6/2026 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.26% | — | Mooveagency Gdpr Cookie Compliance | 16/3/2025 | 17/6/2026 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.26% | — | Mooveagency Gdpr Cookie Compliance | 16/3/2025 | 17/6/2026 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.45% | — | Mooveagency Gdpr Cookie Compliance | 12/3/2025 | 17/6/2026 | The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.32% | — | CHE HAO DUO Used Automobile Agency Beijing CO LTD Guazi Used CARAI | 27/1/2025 | 17/6/2026 | An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via supplying a crafted link. |