Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.2) | 0.30% | — | Checkmk | 13/5/2025 | 17/6/2026 | Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges. | |
| Aplazada | Alta (8.8) | 0.52% | — | Bluewavelabs CheckmateAI | 10/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter. | |
| Analizada | Media (6.3) | 0.32% | — | Checkmk | 8/5/2025 | 17/6/2026 | Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets. | |
| Aplazada | Alta (7.1) | 0.14% | — | Moloni Contribuinte CheckoutAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout contribuinte-checkout allows Stored XSS.This issue affects Contribuinte Checkout: from n/a through <= 2.0.03. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Custom Checkout Fields FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce custom-checkout-fields-for-woocommerce allows Stored XSS.This issue affects Custom Checkout Fields for WooCommerce: from n/a through <= 1.8.3. | |
| Aplazada | Alta (8.1) | 0.50% | — | Bluewavelabs CheckmateAI | 4/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. | |
| Analizada | Media (5.4) | 0.23% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 27/4/2025 | 17/6/2026 | For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties. | |
| Analizada | Media (5.4) | 0.22% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 27/4/2025 | 17/6/2026 | Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list. | |
| Aplazada | Alta (7.1) | 0.29% | — | Hccoder Paypal Express CheckoutAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder PayPal Express Checkout paypal-express-checkout allows Stored XSS.This issue affects PayPal Express Checkout: from n/a through <= 2.1.2. | |
| Aplazada | Alta (7.5) | 0.75% | — | Zamartz Checkout Field Visibility FOR WoocommerceAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zamartz Checkout Field Visibility for WooCommerce checkout-field-visibility-for-woocommerce allows PHP Local File Inclusion.This issue affects Checkout Field Visibility for WooCommerce: from n/a… | |
| Analizada | Alta (7.1) | 0.30% | — | Checkmk | 22/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators. | |
| Analizada | Alta (7.5) | 0.50% | — | Klarna Checkout FOR Woocommerce | 17/4/2025 | 17/6/2026 | The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the… | |
| Aplazada | Media (6.5) | 0.39% | — | Noorsplugin Checkout FOR PaypalAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Checkout for PayPal checkout-for-paypal allows Stored XSS.This issue affects Checkout for PayPal: from n/a through <= 1.0.38. | |
| Aplazada | Media (6.5) | 0.35% | — | Wpwham Checkout Files Upload FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Stored XSS.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Crítica (9.3) | 20% | 💥 Exploit | Lissy93 Web-checkAI | 15/4/2025 | 17/6/2026 | Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). The issue stems from user-controlled input (url) being passed unsanitized into a shell command using exec(), allowing attackers to execute… | |
| Aplazada | Alta (8.5) | 0.49% | — | Ketanajani Duplicate-title-checkerAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ketanajani Duplicate Title Checker duplicate-title-checker allows Blind SQL Injection.This issue affects Duplicate Title Checker: from n/a through <= 1.2. | |
| Analizada | Media (6) | 0.86% | — | Checkmk | 10/4/2025 | 17/6/2026 | Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Mestresdowp Checkout Mestres WPAI | 9/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through <= 8.7.5. | |
| Aplazada | Media (6.5) | 0.46% | — | Aioseo Broken Link CheckerAI | 6/4/2025 | 17/6/2026 | The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to SQL Injection via the 'orderBy' parameter in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Alta (7.1) | 0.39% | — | Lisandragetnet Wc-checkout-getnetAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lisandragetnet Plugin Oficial – Getnet para WooCommerce wc-checkout-getnet allows Reflected XSS.This issue affects Plugin Oficial – Getnet para WooCommerce: from n/a through <= 1.7.3. | |
| Aplazada | Media (6.5) | 0.26% | — | Checklistcom ChecklistAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Checklist checklist allows Stored XSS.This issue affects Checklist: from n/a through <= 1.1.9. | |
| Aplazada | Crítica (9.8) | 0.72% | 💥 PoC | Checkout Mestres DO WPAI | 29/3/2025 | 17/6/2026 | The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Media (4.3) | 0.14% | — | Bsndev Ultimate Security CheckerAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bsndev Ultimate Security Checker ultimate-security-checker allows Cross Site Request Forgery.This issue affects Ultimate Security Checker: from n/a through <= 4.2. | |
| Analizada | Baja (2.3) | 0.21% | — | Checkmk | 26/3/2025 | 17/6/2026 | Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL) | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… |