Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.15% | — | Rankchecker | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration rankchecker-io-integration allows Stored XSS.This issue affects Rankchecker.io Integration: from n/a through <= 1.0.9. | |
| Analizada | Alta (7.7) | 0.38% | — | Heinlein-support Check MK Python API | 3/3/2025 | 17/6/2026 | Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1 | |
| Aplazada | Alta (7.2) | 1.0% | — | Database Backup AND Check Tables Automated With SchedulerAI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.59% | — | Database Backup AND Check Tables Automated With Scheduler 2024AI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Media (6.1) | 0.27% | — | Ericsson Codechecker | 28/2/2025 | 17/6/2026 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the product name in the URL. This results in bypassing the protections… | |
| Analizada | Media (5.4) | 0.29% | — | Thememakers Stripe Checkout | 27/2/2025 | 17/6/2026 | The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' shortcode in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Analizada | Media (5.4) | 0.29% | — | Thememakers Paypal Checkout | 27/2/2025 | 17/6/2026 | The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (6.5) | 0.22% | — | Techmix Direct Checkout Button FOR WoocommerceAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Checkout Button for WooCommerce woo-direct-checkout-button allows Stored XSS.This issue affects Direct Checkout Button for WooCommerce: from n/a through <= 1.0. | |
| Analizada | Media (5.6) | 0.32% | — | Checkmk | 19/2/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators. | |
| Aplazada | Media (4.3) | 0.28% | — | AGE Verification FOR Your Checkout PageAI | 19/2/2025 | 17/6/2026 | Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/class-wc-integration-agechecker-integration.php. | |
| Aplazada | Media (5.4) | 0.18% | — | Wpspellcheck WP Spell CheckAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Cross Site Request Forgery.This issue affects WP Spell Check: from n/a through <= 9.21. | |
| Analizada | Alta (7.5) | 0.40% | — | Checkpoint Gaia OS | 6/2/2025 | 17/6/2026 | In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache. | |
| Aplazada | Alta (7.2) | 1.3% | — | CheckmkAINagvisAI | 4/2/2025 | 17/6/2026 | The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP. | |
| Aplazada | Media (5.4) | 0.58% | — | Checkmk NagvisAI | 4/2/2025 | 17/6/2026 | The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users. | |
| Aplazada | Alta (7.1) | 0.26% | — | Wp24 Domain CheckAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain Check wp24-domain-check allows Reflected XSS.This issue affects WP24 Domain Check: from n/a through <= 1.10.14. | |
| Aplazada | Media (6.5) | 0.23% | — | Saul Morales Pacheco Donate VisaAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects Donate visa: from n/a through <= 1.0.0. | |
| Analizada | Alta (8.2) | 0.25% | — | Ericsson Codechecker | 21/1/2025 | 17/6/2026 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a logged in user, and use the web API with the same permissions, including but not limited to adding,… | |
| Aplazada | Media (6.5) | 0.21% | — | Tamara Solution Tamara CheckoutAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tamara Solution Tamara Checkout tamara-checkout allows Stored XSS.This issue affects Tamara Checkout: from n/a through < 1.9.9.1. | |
| Aplazada | Media (6.4) | 0.28% | — | Noorsplugin Checkout FOR PaypalAI | 17/1/2025 | 17/6/2026 | The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for_paypal' shortcode in all versions up to, and including, 1.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.20% | — | Wp-blackcheckAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stargazer WP-BlackCheck wp-blackcheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through <= 2.7.2. | |
| Aplazada | Alta (7.1) | 0.32% | — | Scott Farrell WP Hosting Performance CheckAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8. | |
| Aplazada | Media (6.1) | 0.19% | — | Woocommerce Check Pincode Zipcode FOR ShippingAI | 9/1/2025 | 17/6/2026 | The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged… | |
| Analizada | Media (4.7) | 0.37% | — | Managewp Broken Link Checker | 26/12/2024 | 17/6/2026 | The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation. | |
| Aplazada | Media (4.9) | 0.85% | — | Database Backup AND Check Tables Automated With SchedulerAI | 24/12/2024 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Media (5.3) | 0.38% | — | Airvantage Warranty CheckerAI | 21/12/2024 | 17/6/2026 | An AirVantage online Warranty Checker tool vulnerability could allow an attacker to perform bulk enumeration of IMEI and Serial Numbers pairs. The AirVantage Warranty Checker is updated to no longer return the IMEI and Serial Number in addition to the warranty status when the Serial Number or IMEI is used to look up… |