Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

401 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.43%—Monsterinsights Userfeedback22/2/202417/6/2026
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it…
ModificadaMedia (4.3)0.45%—Themeisle RSS Aggregator BY Feedzy5/2/202417/6/2026
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated…
ModificadaMedia (6.1)0.36%—Oretnom23 Facebook News Feed Like30/1/202417/6/2026
A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Post Handler. The manipulation of the argument Description with the input <marquee>HACKED</marquee> leads to cross site scripting. The…
ModificadaCrítica (9.8)0.47%—Oretnom23 Facebook News Feed Like30/1/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is an unknown function of the component Post Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-252300.
ModificadaMedia (6.1)0.31%—Oretnom23 Facebook News Feed Like30/1/202417/6/2026
A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New Account Handler. The manipulation of the argument First Name/Last Name with the input <script>alert(1)</script> leads to cross site scripting. The…
ModificadaMedia (5.3)0.54%—Gutengeek GG WOO Feed11/1/202417/6/2026
The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 1.2.4. This makes it possible for unauthenticated attackers to update plugin settings.
ModificadaMedia (4.3)0.32%—Easysocialfeed Easy Social Feed11/1/202417/6/2026
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 6.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized…
ModificadaAlta (7.2)0.62%—Svnlabs Html5 MP3 Player With Folder Feedburner Playlist Free8/1/202417/6/2026
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.
ModificadaMedia (5.4)0.31%—Themeisle RSS Aggregator BY Feedzy6/1/202417/6/2026
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaMedia (5.4)0.29%—Themeisle RSS Aggregator BY Feedzy6/1/202417/6/2026
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers,…
ModificadaAlta (8.8)0.22%—Smashballoon Custom Twitter Feeds5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.
ModificadaAlta (8.8)0.25%—Pixelyoursite Product Catalog Feed17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
ModificadaAlta (8.8)0.26%—Whereyoursolutionis FIX MY Feed RSS Repair17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Innovative Solutions Fix My Feed RSS Repair.This issue affects Fix My Feed RSS Repair: from n/a through 1.4.
ModificadaMedia (5.4)0.39%—ADS BY Datafeedr.com15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in datafeedr.Com Ads by datafeedr.Com allows Stored XSS.This issue affects Ads by datafeedr.Com: from n/a through 1.2.0.
ModificadaMedia (5.3)0.50%—Blmodules CSV Feeds PRO27/11/202317/6/2026
In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of…
ModificadaMedia (6.1)0.41%—Photofeed Photo Feed14/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Feed plugin <= 2.2.1 versions.
ModificadaAlta (8.8)0.32%—Kebo Twitter Feed Project Kebo Twitter Feed13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kebo Kebo Twitter Feed plugin <= 1.5.12 versions.
ModificadaAlta (8.8)0.30%—Accesspressthemes WP Tfeed13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes WP TFeed plugin <= 1.6.9 versions.
ModificadaMedia (4.8)0.39%—Web-settler Social Feed | ALL Social Media IN ONE Place8/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one place plugin <= 1.5.4.6 versions.
ModificadaMedia (5.4)0.46%—Web-settler Social Feed7/11/202317/6/2026
The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcode in all versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaCrítica (9.8)0.56%—Bontheme Socialfeed - Photos & Video Using Instagram API3/11/202317/6/2026
Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate data via a HTTP call.
ModificadaCrítica (9.8)0.64%—Blmodules CSV Feeds PRO31/10/202317/6/2026
In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaCrítica (9.8)2.2%—ADS BY Datafeedr.com30/10/202317/6/2026
The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are limited, they cannot be specified…
ModificadaMedia (6.1)0.35%—Monsterinsights Userfeedback27/10/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions.
ModificadaMedia (6.1)0.33%—Arrowplugins THE Awesome Feed26/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions.
Orbitaley — Vulnerabilidades