Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.86% | — | Wpmudev UpdatesAI | 12/8/2026 | 26/8/2026 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote… | |
| Aplazada | Media (5.3) | 0.37% | — | Npm-check-updatesAI | 10/8/2026 | 24/9/2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or… | |
| Aplazada | Alta (7.1) | 0.16% | — | Razer RzupdateserviceAI | 3/8/2026 | 12/8/2026 | A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to… | |
| Aplazada | Media (6.1) | 0.35% | — | Easyupdatesmanager Easy Updates ManagerAI | 28/5/2026 | 17/6/2026 | The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attackers to inject arbitrary web… | |
| Aplazada | Media (4.3) | 0.13% | — | Plugin Updates BlockerAI | 11/9/2025 | 17/6/2026 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the pub_save action handler. This makes it possible for unauthenticated attackers to disable or enable plugin updates via a… | |
| Aplazada | Alta (8.8) | 0.37% | — | Aweos Gmbh Email Notifications FOR UpdatesAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.42% | — | Rachel Cherry Lock Your UpdatesAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates lock-your-updates allows Reflected XSS.This issue affects Lock Your Updates: from n/a through <= 1.1. | |
| Aplazada | Alta (8.8) | 0.39% | — | Email Notifications FOR UpdatesAI | 5/4/2025 | 17/6/2026 | The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.29% | — | David Wood Latest Custom Post Type UpdatesAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest Custom Post Type Updates latest-custom-post-type-updates allows Reflected XSS.This issue affects Latest Custom Post Type Updates: from n/a through <= 1.3.0. | |
| Analizada | Media (4.3) | 0.17% | — | Exeebit Disable Auto Updates | 19/2/2025 | 17/6/2026 | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged… | |
| Aplazada | Alta (7.1) | 0.26% | — | Irshad A Khan Services Updates FOR CustomersAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0. | |
| Aplazada | Alta (8.3) | 0.12% | — | Intel Seamless Firmware UpdatesAI | 16/9/2024 | 17/6/2026 | Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (5.4) | 0.36% | — | Ipushpull Live Updates From Excel | 31/10/2023 | 17/6/2026 | The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.8) | 0.66% | — | Microsoft Windows Defender Security Intelligence Updates | 12/9/2023 | 17/6/2026 | Windows Defender Attack Surface Reduction Security Feature Bypass | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Defender Security Intelligence Updates | 14/2/2023 | 19/8/2026 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | |
| Modificada | Crítica (9.8) | 0.90% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 27/10/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=. | |
| Modificada | Media (4.8) | 0.59% | — | Linkedin Company Updates Project Linkedin Company Updates | 17/7/2022 | 17/6/2026 | The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.3) | 0.89% | — | Easyupdatesmanager Easy Updates Manager | 27/8/2019 | 17/6/2026 | The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error. | |
| Modificada | Alta (8.1) | 3.3% | — | Lenovo Updates | 10/4/2017 | 17/6/2026 | Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code. |