Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.58% | — | Ancorathemes Apollo Night Club DJ Event Wordpress ThemeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Apollo | Night Club, DJ Event WordPress Theme apollo allows PHP Local File Inclusion.This issue affects Apollo | Night Club, DJ Event WordPress Theme: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Blend Media Wordpress CTAAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through <= 2.1.2. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Builderall Builder FOR WordpressAI | 5/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Slimndap Theater FOR WordpressAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.19. | |
| Aplazada | Alta (7.5) | 0.28% | — | Mikado-themes Pawfriends - PET Shop AND Veterinary Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.24% | — | Gt3themes Soho - Photography Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes SOHO - Photography WordPress Theme soho allows DOM-Based XSS.This issue affects SOHO - Photography WordPress Theme: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Gt3themes Oyster - Photography Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyster - Photography WordPress Theme: from n/a through <= 4.4.3. | |
| Aplazada | Alta (7.1) | 0.24% | — | BAS Schuiling Feedwordpress Advanced FiltersAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bas Schuiling FeedWordPress Advanced Filters faf allows Reflected XSS.This issue affects FeedWordPress Advanced Filters: from n/a through <= 0.6.2. | |
| Aplazada | Media (6.5) | 0.26% | — | Elextensions Elex Wordpress Helpdesk Customer Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.3.5. | |
| Aplazada | Media (6.5) | 0.26% | — | Passionatebrains Ga4wp Google Analytics FOR WordpressAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Rtcamp Rtmedia FOR Wordpress Buddypress AND BbpressAI | 19/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8. | |
| Aplazada | Media (6.4) | 0.27% | — | Collect.chat Chatbot FOR WordpressAI | 14/2/2026 | 17/6/2026 | The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (7.1) | 0.48% | — | Kostasmitroglou Password Management Application | 12/2/2026 | 17/6/2026 | thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts. | |
| Modificada | Alta (7.1) | 0.48% | — | Kostasmitroglou Password Management Application | 12/2/2026 | 17/6/2026 | TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive system information. | |
| Aplazada | Media (4.6) | 0.25% | — | MSN Password RecoveryAI | 11/2/2026 | 17/6/2026 | MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to… | |
| Aplazada | Media (4.6) | 0.41% | — | Krylack ZIP Password RecoveryAI | 11/2/2026 | 17/6/2026 | ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file. | |
| Aplazada | Media (6.7) | 0.22% | — | MSN Password RecoveryAI | 11/2/2026 | 17/6/2026 | MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration… | |
| Aplazada | Media (4.6) | 0.30% | — | TOP Password Software Dialup Password RecoveryAI | 11/2/2026 | 17/6/2026 | Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields. | |
| Aplazada | Media (4.6) | 0.30% | — | TOP Password Firefox Password RecoveryAI | 11/2/2026 | 17/6/2026 | Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields. | |
| Aplazada | Media (4.6) | 0.30% | — | Gtalk Password FinderAI | 11/2/2026 | 17/6/2026 | GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.30% | — | Keepass Password SafeAI | 11/2/2026 | 17/6/2026 | KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash. | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress Server LOG ViewerAI | 11/2/2026 | 17/6/2026 | WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface. | |
| Analizada | Alta (7.5) | 3.9% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 10/2/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Xpoda Turkiye Information Technology INC Password ModuleAI | 9/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026. | |
| Aplazada | Media (6.7) | 0.45% | — | Spotftp-ftp Password RecoverAI | 7/2/2026 | 17/6/2026 | SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the application crash. |