Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.0% | — | Weplugins WP Maps | 12/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. | |
| Modificada | Media (5.4) | 1.1% | — | Codecabin WP GO Maps | 9/8/2019 | 17/6/2026 | The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. | |
| Modificada | Alta (8.8) | 1.0% | — | Fla-shop Html5 Maps | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Codecabin WP GO Maps | 2/4/2019 | 17/6/2026 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement. | |
| Modificada | Media (6.1) | 3.2% | 💥 Exploit | Codecabin WP GO Maps | 22/3/2019 | 17/6/2026 | The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO. | |
| Modificada | Alta (8.8) | 0.80% | — | Mapsvg Lite | 4/2/2019 | 17/6/2026 | MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via the victim must be logged in to… | |
| Modificada | Media (4.8) | 0.68% | — | Google XML Sitemaps Project Google XML Sitemaps | 9/1/2019 | 17/6/2026 | Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.2% | — | Atmist Snazzy Maps | 3/10/2018 | 17/6/2026 | The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter. | |
| Modificada | Media (5.9) | 1.6% | — | Mapsplugin Googlemaps | 28/9/2017 | 17/6/2026 | The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7428. | |
| Modificada | Crítica (9.8) | 2.2% | — | Mapsplugin Googlemaps | 14/9/2017 | 17/6/2026 | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php. | |
| Modificada | Alta (7.5) | 1.9% | — | Mapsplugin Googlemaps | 7/9/2017 | 17/6/2026 | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php. | |
| Modificada | Media (6.1) | 0.90% | — | Mapsplugin Googlemaps | 29/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!. | |
| Modificada | Alta (7.5) | 1.6% | — | Mapsplugin Googlemaps | 29/8/2017 | 17/6/2026 | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism. | |
| Modificada | Media (5.3) | 1.1% | — | Mapsplugin Googlemaps | 29/8/2017 | 17/6/2026 | Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!. | |
| Modificada | Media (6.1) | 0.76% | — | Mapsplugin Googlemaps | 28/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Crítica (9.8) | 4.8% | — | Debian LinuxOsgeo Mapserver | 15/3/2017 | 17/6/2026 | Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests. | |
| Modificada | Alta (7.5) | 1.5% | — | Osgeo Mapserver | 8/12/2016 | 17/6/2026 | In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails. | |
| Modificada | Media (6.1) | 4.4% | 💥 Exploit | Hero-maps-pro Project Hero-maps-pro | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin hero-maps-pro v2.1.0 | |
| Modificada | Alta (7.5) | 2.2% | — | OLD GSI Maps | 19/6/2016 | 17/6/2026 | Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (5.8) | 2.1% | — | Nokia Maps & Places Project Nokia Maps & Places | 1/7/2015 | 17/6/2026 | Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as a cross-site scripting (XSS)… | |
| Modificada | Media (5) | 2.0% | — | Infoware Mapsuite | 1/12/2014 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to trigger requests to intranet servers via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Infoware Mapsuite | 1/12/2014 | 17/6/2026 | Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.5% | — | Codecabin WP GO Maps | 22/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php. | |
| Modificada | Media (5.4) | 0.29% | — | Daum Maps - Subway | 2/10/2014 | 17/6/2026 | The Daum Maps - Subway (aka net.daum.android.map) application 3.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |