Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Mapster WP MapsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions. | |
| Aplazada | Crítica (9.1) | 0.19% | — | Bestwebsoft Google MapsAI | 4/10/2026 | 6/10/2026 | The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API… | |
| Aplazada | Media (6.5) | 0.16% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Easy Google MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | |
| Aplazada | Alta (7.5) | 0.75% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (6.4) | 0.33% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.46% | — | Mapster WP MapsAI | 18/9/2026 | 19/9/2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the… | |
| Pendiente de análisis | Media (5.3) | 0.50% | — | MapserverAI | 17/9/2026 | 30/9/2026 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(),… | |
| Pendiente de análisis | Alta (8.2) | 0.68% | — | MapserverAIPostgresqlAIPostgisAI | 17/9/2026 | 24/9/2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does… | |
| Aplazada | Alta (7.6) | 0.38% | — | Weplugins WP MapsAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Supsystic Ultimate MapsAI | 3/9/2026 | 5/9/2026 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3. | |
| Analizada | Media (5.3) | 0.56% | — | Elastic Maps Server | 2/9/2026 | 8/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended… | |
| Aplazada | Media (5.3) | 0.40% | — | WP GO MapsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Interactive GEO MapsAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | |
| Aplazada | Media (5.4) | 0.22% | — | MapsvgAI | 31/8/2026 | 2/9/2026 | Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. | |
| Pendiente de análisis | Alta (7) | 0.28% | — | Element Maps-ngAI | 27/8/2026 | 28/8/2026 | A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Maps Marker PROAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Weplugins WP MapsAI | 19/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request. | |
| Aplazada | Alta (8.6) | 0.58% | — | Mediawiki MapsAI | 18/8/2026 | 9/9/2026 | Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a… | |
| Aplazada | Alta (7.5) | 0.35% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.33% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. |