Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.16% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory… | |
| Aplazada | Alta (7) | 0.34% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation… | |
| Aplazada | Alta (8.6) | 0.59% | — | Codexonics Prime MoverAI | 1/10/2026 | 2/10/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by… | |
| Aplazada | Alta (8.5) | 0.10% | — | Eset AV RemoverAI | 9/9/2026 | 9/9/2026 | Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC. | |
| Pendiente de análisis | Media (6.5) | 0.39% | 💥 PoC | Opswat Appremover DriverAI | 16/7/2026 | 17/7/2026 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation. | |
| Aplazada | Media (4.3) | 0.27% | — | Prasadkirpekar WP Meta AND Date RemoverAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6. | |
| Aplazada | Media (4.8) | 0.19% | — | Bluelabsio Records-moverAI | 7/1/2026 | 17/6/2026 | A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes sql injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to fix this issue. Patch name:… | |
| Analizada | Alta (8.1) | 1.5% | — | Qnap Malware Remover | 2/1/2026 | 17/6/2026 | An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later | |
| Aplazada | Media (5.3) | 0.29% | — | Joelhardi User Spam RemoverAI | 9/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Joel User Spam Remover user-spam-remover allows Retrieve Embedded Sensitive Data.This issue affects User Spam Remover: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.15% | — | Rajesh Broken-links-removerAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Broken Links Remover broken-links-remover allows Stored XSS.This issue affects Broken Links Remover: from n/a through <= 1.2.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | Dan-lucian Stefancu Empty-tags-removerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan-Lucian Stefancu Empty Tags Remover empty-tags-remover allows Reflected XSS.This issue affects Empty Tags Remover: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Fastmover Plugins Last Updated ColumnAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column plugins-last-updated-column allows Cross Site Request Forgery.This issue affects Plugins Last Updated Column: from n/a through <= 0.1.3. | |
| Modificada | Alta (8.8) | 0.19% | — | Venugopal Comment Date AND Gravatar Remover | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0. | |
| Modificada | Media (4.5) | 0.50% | 💥 PoC | Oretnom23 Packers AND Movers Management System | 6/2/2025 | 5/7/2026 | Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user. | |
| Analizada | Media (6.4) | 1.0% | 💥 PoC | Oretnom23 Packers AND Movers Management System | 3/2/2025 | 17/6/2026 | SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation. | |
| Aplazada | Media (5.4) | 0.39% | — | Prasadkirpekar WP Meta AND Date RemoverAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in prasadkirpekar WP Meta and Date Remover wp-meta-and-date-remover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meta and Date Remover: from n/a through <= 2.3.0. | |
| Analizada | Alta (8.8) | 0.92% | 💥 PoC | Oretnom23 Packers AND Movers Management System | 24/10/2024 | 17/6/2026 | A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id | |
| Aplazada | Media (4.4) | 0.29% | — | Visual Footer Credit RemoverAI | 14/5/2024 | 17/6/2026 | The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Media (4.3) | 0.43% | — | Admin BAR RemoverAI | 2/5/2024 | 17/6/2026 | The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_form() function in all versions up to, and including, 1.0.2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable or disable… | |
| Modificada | Alta (7.5) | 0.51% | — | Joelhardi User Spam Remover | 10/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0. | |
| Aplazada | Alta (8.1) | 0.62% | 💥 PoC | Easeus MobimoverAI | 7/3/2024 | 17/6/2026 | Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory. | |
| Modificada | Alta (8) | 2.7% | — | Microsoft Azure Storage Mover | 9/1/2024 | 17/6/2026 | Azure Storage Mover Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Codexonics Prime Mover | 8/1/2024 | 17/6/2026 | The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files. | |
| Modificada | Alta (7.2) | 1.2% | — | Oretnom23 Packers AND Movers Management System | 30/11/2023 | 17/6/2026 | SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file. | |
| Modificada | Media (5.4) | 0.38% | — | Prasadkirpekar WP Meta AND Date Remover | 31/10/2023 | 17/6/2026 | The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform… |