Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.49%—Responsivefilemanager9/5/202317/6/2026
Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file.
ModificadaMedia (5.4)0.36%—Simple Youtube Responsive Project Simple Youtube Responsive4/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Eirudo Simple YouTube Responsive plugin <= 2.5 versions.
ModificadaMedia (4.8)0.49%—Drupal Responsive Menus1/5/202317/6/2026
A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation leads to cross site scripting. The attack…
ModificadaMedia (5.4)0.38%—Theme Blvd Responsive Google Maps Project Theme Blvd Responsive Google Maps23/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.
ModificadaMedia (6.1)0.56%—I13websolution Responsive Filterable Portfolio18/4/202317/6/2026
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (4.8)0.39%—Wpdevart Responsive Vertical Icon Menu4/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 versions.
ModificadaMedia (5.4)0.49%—Wpdarko Responsive Pricing Table28/3/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.6 versions.
ModificadaCrítica (9.8)0.87%💥 PoCFabian Responsive Hotel Site19/3/202317/6/2026
A vulnerability classified as critical has been found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file messages.php of the component Newsletter Log Handler. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit…
ModificadaMedia (5.4)0.47%—Eaglevisionit Evision Responsive Column Layout Shortcodes6/3/202317/6/2026
The eVision Responsive Column Layout Shortcodes WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.23%—Wpdevart Responsive Vertical Icon Menu28/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion.
ModificadaMedia (6.1)0.54%—Oretnom23 Simple Responsive Tourism Website26/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Responsive Tourism Website 1.0. This affects an unknown part of the file /tourism/rate_review.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to…
ModificadaMedia (5.4)0.47%—WP Responsive Testimonials Slider AND Widget Project WP Responsive Testimonials Slider AND Widget21/2/202317/6/2026
The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.48%—Responsive Gallery Grid Project Responsive Gallery Grid13/2/202317/6/2026
The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.62%—Responsivevoice Text TO Speech6/2/202317/6/2026
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.8)8.6%💥 ExploitTecrail Responsive Filemanager2/2/202317/6/2026
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
ModificadaMedia (5.4)0.48%—Noorsplugin Responsive Lightbox219/12/202217/6/2026
The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.2)1.3%—Oxilab Responsive Tabs25/7/202217/6/2026
Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.
ModificadaCrítica (9.8)1.0%—Tecrail Responsive Filemanager25/7/202217/6/2026
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended…
ModificadaCrítica (9.8)2.0%—Responsive Online Blog Project Responsive Online Blog2/6/202217/6/2026
Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.
ModificadaMedia (4.8)0.59%—Wpshopmart Tabs Responsive23/5/202217/6/2026
The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.60%—Wpdarko Responsive Tabs11/4/202217/6/2026
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
ModificadaAlta (8.8)1.3%—Expresstech Responsive Menu18/3/202217/6/2026
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
ModificadaMedia (4.8)0.60%—Html5 Responsive FAQ Project Html5 Responsive FAQ14/3/202217/6/2026
The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaMedia (5.4)0.60%—Magnigenie WP Responsive Menu28/2/202217/6/2026
The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting…
ModificadaMedia (6.5)3.1%💥 ExploitThinkupthemes Responsive Vector Maps7/2/202217/6/2026
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server
Orbitaley — Vulnerabilidades