Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.28% | — | IBM Infosphere Master Data Management | 27/1/2025 | 17/6/2026 | IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 0.58% | — | Addonmaster Post Grid Master | 24/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows PHP Local File Inclusion.This issue affects Post Grid Master: from n/a through <= 3.4.12. | |
| Aplazada | Media (4.3) | 0.24% | — | Cmsmasters THE Buzz ClubAI | 18/1/2025 | 17/6/2026 | The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cmsmasters_hide_admin_notice' function in all versions up to, and including, 2.0.4. This makes it… | |
| Aplazada | Alta (7.1) | 0.20% | — | Master Software Solutions WP Vtiger SynchronizationAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.1) | 0.33% | — | Bavington WP HeadmasterAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bavington WP Headmaster wp-headmaster allows Reflected XSS.This issue affects WP Headmaster: from n/a through <= 0.3. | |
| Analizada | Media (6.1) | 0.36% | — | Edmonparker Contact Form Master | 11/1/2025 | 17/6/2026 | The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Crítica (9.8) | 1.1% | — | Addonmaster Post Grid Master | 9/1/2025 | 17/6/2026 | The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the 'locate_template' function. This makes it possible for… | |
| Analizada | Media (5.4) | 0.39% | — | Master-addons Master Addons | 7/1/2025 | 17/6/2026 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Tooltip module in all versions up to, and including, 2.0.6.7 due to insufficient input sanitization and output escaping on user… | |
| Analizada | Media (6.1) | 0.36% | — | Goodlayers Tour Master | 6/1/2025 | 17/6/2026 | The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks. | |
| Aplazada | Crítica (9.1) | 1.3% | 💥 PoC | Ludwig YOU WpmastertoolkitAI | 2/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1. | |
| Aplazada | Media (4.9) | 0.54% | — | Ludwig YOU WpmastertoolkitAI | 2/1/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Path Traversal.This issue affects WPMasterToolKit: from n/a through <= 1.13.1. | |
| Modificada | Alta (8.8) | 0.21% | — | Stylemixthemes Masterstudy LMS | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through <= 3.2.1. | |
| Analizada | Media (5.3) | 0.39% | — | Code-projects Online Exam Mastering System | 22/12/2024 | 17/6/2026 | A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file /sign.php?q=account.php. The manipulation of the argument name/gender/college leads to cross site scripting. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.55% | — | Code-projects Online Exam Mastering System | 22/12/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.55% | — | Code-projects Online Exam Mastering System | 22/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /update.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Alta (7.1) | 0.20% | — | Fzmaster XPD Reduce Image FilesizeAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fzmaster XPD Reduce Image Filesize xpd-reduce-image-filesize allows Stored XSS.This issue affects XPD Reduce Image Filesize: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.47% | — | Expresstechsoftwares Quiz AND Survey MasterAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Mobatime Network Master Clock DTS 4801AI | 10/12/2024 | 17/6/2026 | MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials. | |
| Aplazada | Media (6.4) | 0.27% | — | Cmsmasters Elementor AddonAI | 3/12/2024 | 17/6/2026 | The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.14.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.3) | 0.31% | — | Masterstack ImgcapAI | 25/11/2024 | 4/7/2026 | masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit. | |
| Aplazada | Media (6.5) | 0.39% | — | Intelligentdesign Keymaster Chord Notation FreeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligentDesign Keymaster Chord Notation Free keymaster-chord-notation-free allows Stored XSS.This issue affects Keymaster Chord Notation Free: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.1) | 0.20% | — | Matt Rude MDR Webmaster ToolsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matt Rude MDR Webmaster Tools mdr-webmaster-tools allows Stored XSS.This issue affects MDR Webmaster Tools: from n/a through <= 1.1. | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Utility FOR Overclocking Control | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Monitoring Software Development KIT | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Media (6.5) | 0.25% | — | Masterbip Para ElementorAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masterbip MasterBip para Elementor masterbip-for-elementor allows DOM-Based XSS.This issue affects MasterBip para Elementor: from n/a through <= 1.6.3. |