Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.16%—Codexonics Prime MoverAI1/10/20262/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory…
AplazadaAlta (7)0.34%—Codexonics Prime MoverAI1/10/20262/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation…
AplazadaAlta (8.6)0.59%—Codexonics Prime MoverAI1/10/20262/10/2026
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by…
AplazadaAlta (8.5)0.10%—Eset AV RemoverAI9/9/20269/9/2026
Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.
Pendiente de análisisMedia (6.5)0.39%💥 PoCOpswat Appremover DriverAI16/7/202617/7/2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.
AplazadaMedia (4.3)0.27%—Prasadkirpekar WP Meta AND Date RemoverAI27/5/202617/6/2026
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.
AplazadaMedia (4.8)0.19%—Bluelabsio Records-moverAI7/1/202617/6/2026
A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes sql injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to fix this issue. Patch name:…
AnalizadaAlta (8.1)1.5%—Qnap Malware Remover2/1/202617/6/2026
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later
AplazadaMedia (5.3)0.29%—Joelhardi User Spam RemoverAI9/12/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Joel User Spam Remover user-spam-remover allows Retrieve Embedded Sensitive Data.This issue affects User Spam Remover: from n/a through <= 1.1.
AplazadaAlta (7.1)0.15%—Rajesh Broken-links-removerAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Broken Links Remover broken-links-remover allows Stored XSS.This issue affects Broken Links Remover: from n/a through <= 1.2.2.
AplazadaAlta (7.1)0.29%—Dan-lucian Stefancu Empty-tags-removerAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan-Lucian Stefancu Empty Tags Remover empty-tags-remover allows Reflected XSS.This issue affects Empty Tags Remover: from n/a through <= 1.0.
AplazadaMedia (4.3)0.17%—Fastmover Plugins Last Updated ColumnAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column plugins-last-updated-column allows Cross Site Request Forgery.This issue affects Plugins Last Updated Column: from n/a through <= 0.1.3.
ModificadaAlta (8.8)0.19%—Venugopal Comment Date AND Gravatar Remover11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0.
ModificadaMedia (4.5)0.50%💥 PoCOretnom23 Packers AND Movers Management System6/2/20255/7/2026
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.
AnalizadaMedia (6.4)1.0%💥 PoCOretnom23 Packers AND Movers Management System3/2/202517/6/2026
SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.
AplazadaMedia (5.4)0.39%—Prasadkirpekar WP Meta AND Date RemoverAI9/12/202417/6/2026
Missing Authorization vulnerability in prasadkirpekar WP Meta and Date Remover wp-meta-and-date-remover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meta and Date Remover: from n/a through <= 2.3.0.
AnalizadaAlta (8.8)0.92%💥 PoCOretnom23 Packers AND Movers Management System24/10/202417/6/2026
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
AplazadaMedia (4.4)0.29%—Visual Footer Credit RemoverAI14/5/202417/6/2026
The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to…
AplazadaMedia (4.3)0.43%—Admin BAR RemoverAI2/5/202417/6/2026
The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_form() function in all versions up to, and including, 1.0.2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable or disable…
ModificadaAlta (7.5)0.51%—Joelhardi User Spam Remover10/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.
AplazadaAlta (8.1)0.62%💥 PoCEaseus MobimoverAI7/3/202417/6/2026
Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.
ModificadaAlta (8)2.7%—Microsoft Azure Storage Mover9/1/202417/6/2026
Azure Storage Mover Remote Code Execution Vulnerability
ModificadaAlta (7.5)40%💥 ExploitCodexonics Prime Mover8/1/202417/6/2026
The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.
ModificadaAlta (7.2)1.2%—Oretnom23 Packers AND Movers Management System30/11/202317/6/2026
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.
ModificadaMedia (5.4)0.38%—Prasadkirpekar WP Meta AND Date Remover31/10/202317/6/2026
The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform…
Orbitaley — Vulnerabilidades