Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | |
| Aplazada | Media (4.4) | 0.21% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Booking-wp-plugin BooklyAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Booking-wp-plugin BooklyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Fantasticplugins Sumo Reward PointsAI | 23/7/2026 | 23/7/2026 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the… | |
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Analizada | Crítica (10) | 0.43% | — | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Aplazada | Alta (8.7) | 0.37% | — | Getgrav Grav-plugin-apiAI | 21/7/2026 | 23/7/2026 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every… | |
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Aplazada | Media (5.4) | 0.14% | 💥 PoC | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Aplazada | Alta (8.2) | 0.38% | — | Dancer Plugin Auth GoogleAI | 17/7/2026 | 11/8/2026 | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token… | |
| Aplazada | Alta (7.1) | 0.34% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 17/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accepts credentials via the Authorization and X-API-Token headers (set… | |
| Aplazada | Alta (8.2) | 0.43% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 23/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server access logs, leaked via the Referer header,… | |
| Aplazada | Baja (2.3) | 0.14% | — | Getgrav Grav-plugin-loginAI | 17/7/2026 | 17/7/2026 | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce or Origin/Referer check. Because Grav core dispatches the task from… | |
| Aplazada | Alta (8.7) | 0.44% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 17/7/2026 | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from super-admin users to achieve full instance… | |
| Aplazada | Alta (8.6) | 0.39% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 21/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owning user's full account object, so a key created with limited scopes… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI | 16/7/2026 | 16/7/2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn… | |
| Aplazada | Media (5.4) | 0.14% | — | Appointment Booking PluginAI | 16/7/2026 | 16/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 17/7/2026 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 16/7/2026 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.19% | — | Pluginops Landing Page BuilderAI | 16/7/2026 | 17/7/2026 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible… | |
| Aplazada | Media (6.7) | 0.72% | — | Nocobase Plugin BackupsAI | 15/7/2026 | 18/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command strings executed with Node.js… | |
| Aplazada | Media (6.8) | 0.47% | — | NocobaseAINocobase Plugin Collection SQLAI | 15/7/2026 | 16/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that… |