Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.49% | — | Responsivefilemanager | 9/5/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file. | |
| Modificada | Media (5.4) | 0.36% | — | Simple Youtube Responsive Project Simple Youtube Responsive | 4/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 versions. | |
| Modificada | Media (4.8) | 0.49% | — | Drupal Responsive Menus | 1/5/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation leads to cross site scripting. The attack… | |
| Modificada | Media (5.4) | 0.38% | — | Theme Blvd Responsive Google Maps Project Theme Blvd Responsive Google Maps | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions. | |
| Modificada | Media (6.1) | 0.56% | — | I13websolution Responsive Filterable Portfolio | 18/4/2023 | 17/6/2026 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (4.8) | 0.39% | — | Wpdevart Responsive Vertical Icon Menu | 4/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 versions. | |
| Modificada | Media (5.4) | 0.49% | — | Wpdarko Responsive Pricing Table | 28/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions. | |
| Modificada | Crítica (9.8) | 0.87% | 💥 PoC | Fabian Responsive Hotel Site | 19/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file messages.php of the component Newsletter Log Handler. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Media (5.4) | 0.47% | — | Eaglevisionit Evision Responsive Column Layout Shortcodes | 6/3/2023 | 17/6/2026 | The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.23% | — | Wpdevart Responsive Vertical Icon Menu | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion. | |
| Modificada | Media (6.1) | 0.54% | — | Oretnom23 Simple Responsive Tourism Website | 26/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Responsive Tourism Website 1.0. This affects an unknown part of the file /tourism/rate_review.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to… | |
| Modificada | Media (5.4) | 0.47% | — | WP Responsive Testimonials Slider AND Widget Project WP Responsive Testimonials Slider AND Widget | 21/2/2023 | 17/6/2026 | The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.48% | — | Responsive Gallery Grid Project Responsive Gallery Grid | 13/2/2023 | 17/6/2026 | The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.62% | — | Responsivevoice Text TO Speech | 6/2/2023 | 17/6/2026 | The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 8.6% | 💥 Exploit | Tecrail Responsive Filemanager | 2/2/2023 | 17/6/2026 | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. | |
| Modificada | Media (5.4) | 0.48% | — | Noorsplugin Responsive Lightbox2 | 19/12/2022 | 17/6/2026 | The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.2) | 1.3% | — | Oxilab Responsive Tabs | 25/7/2022 | 17/6/2026 | Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress. | |
| Modificada | Crítica (9.8) | 1.0% | — | Tecrail Responsive Filemanager | 25/7/2022 | 17/6/2026 | A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended… | |
| Modificada | Crítica (9.8) | 2.0% | — | Responsive Online Blog Project Responsive Online Blog | 2/6/2022 | 17/6/2026 | Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php. | |
| Modificada | Media (4.8) | 0.59% | — | Wpshopmart Tabs Responsive | 23/5/2022 | 17/6/2026 | The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.60% | — | Wpdarko Responsive Tabs | 11/4/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5 | |
| Modificada | Alta (8.8) | 1.3% | — | Expresstech Responsive Menu | 18/3/2022 | 17/6/2026 | Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7). | |
| Modificada | Media (4.8) | 0.60% | — | Html5 Responsive FAQ Project Html5 Responsive FAQ | 14/3/2022 | 17/6/2026 | The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.60% | — | Magnigenie WP Responsive Menu | 28/2/2022 | 17/6/2026 | The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting… | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Thinkupthemes Responsive Vector Maps | 7/2/2022 | 17/6/2026 | The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server |