Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.30% | — | Dwbooster Calculated Fields Form | 11/1/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Modificada | Alta (7.5) | 0.52% | — | Advancedcustomfields Advanced Custom Fields | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through 6.0.2. | |
| Modificada | Media (5.4) | 0.29% | — | Codepeople Calculated Fields Form | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28. | |
| Modificada | Alta (8.8) | 0.44% | — | Andersthorborg Advanced Custom Fields\ | 29/12/2023 | 17/6/2026 | Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12. | |
| Modificada | Media (4.8) | 0.44% | — | Codesmade Autocomplete Location Field Contact Form 7 | 18/12/2023 | 17/6/2026 | The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… | |
| Modificada | Media (6.1) | 0.66% | — | Mantisbt Linked Custom Fields | 11/12/2023 | 17/6/2026 | The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when… | |
| Modificada | Media (5.4) | 0.51% | — | Acfextended Advanced Custom Fields Extended | 20/10/2023 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_form' shortcode in versions up to, and including, 0.8.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.8) | 0.32% | — | GET Custom Field Values Project GET Custom Field Values | 18/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <= 4.0.1 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Pixelgrade Pixfields | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.3) | 0.56% | — | Bestwebsoft Profile Extra Fields | 6/10/2023 | 17/6/2026 | The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data,… | |
| Modificada | Alta (7.8) | 0.17% | — | Nvidia Bluefield 1 FirmwareNvidia Bluefield 2 LTS FirmwareNvidia Bluefield 2 GA FirmwareNvidia Bluefield 3 GA Firmware | 12/9/2023 | 17/6/2026 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Fieldthemes Fieldpopupnewsletter | 8/9/2023 | 17/6/2026 | FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php. | |
| Modificada | Media (5.4) | 2.0% | — | Advancedcustomfields Advanced Custom Fields | 21/8/2023 | 17/6/2026 | Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 allows a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product with the administrative privilege. | |
| Modificada | Media (4.8) | 0.44% | — | Custom Field FOR WP JOB Manager Project Custom Field FOR WP JOB Manager | 14/8/2023 | 17/6/2026 | The Custom Field For WP Job Manager WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.41% | — | Wpgogo Custom Field Template | 7/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 versions. | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Media (4.8) | 0.37% | — | Custom Field FOR WP JOB Manager Project Custom Field FOR WP JOB Manager | 27/7/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Custom Field For WP Job Manager plugin <= 1.1 versions. | |
| Modificada | Media (4.3) | 0.50% | — | Navz ACF Photo Gallery Field | 27/7/2023 | 17/6/2026 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with subscriber-level permissions or above, to update… | |
| Modificada | Alta (8.8) | 0.32% | — | Wpgogo Custom Field Template | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Wpgogo Custom Field Template | 1/7/2023 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the edit_meta_value() function. This makes it possible for unauthenticated attackers to edit meta field values via a forged request… | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Wpdesk Flexible Checkout Fields | 7/6/2023 | 17/6/2026 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via… | |
| Modificada | Alta (7.5) | 1.1% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 7/6/2023 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service. | |
| Modificada | Media (6.1) | 0.95% | 💥 Exploit | Themeisle Product Addons & Fields FOR Woocommerce | 30/5/2023 | 17/6/2026 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting. | |
| Modificada | Crítica (9.8) | 24% | — | Supcontech Simfield Firmware | 27/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functionality of the file /admin/reportupload.aspx. The manipulation of the argument files[] leads to unrestricted upload. The attack may be launched remotely. The exploit has… |