Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

2432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.33%—Really-simple-plugins ComplianzAI23/7/202612/8/2026
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
AplazadaAlta (7.2)0.54%—Really-simple-plugins ComplianzAI23/7/202623/7/2026
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
AplazadaMedia (4.4)0.21%—Really-simple-plugins ComplianzAI23/7/202623/7/2026
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
AplazadaCrítica (9.3)0.40%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
AplazadaAlta (7.1)0.25%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
AplazadaAlta (7.2)0.32%—Fantasticplugins Sumo Reward PointsAI23/7/202623/7/2026
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the…
AplazadaMedia (5.3)0.30%—Wp-feedstats Wordpress PluginAI22/7/202622/7/2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
AnalizadaCrítica (10)0.43%—Oracle Http ServerOracle Weblogic Server Proxy Plug-in21/7/20265/8/2026
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
AnalizadaCrítica (9.8)0.51%—Oracle Http ServerOracle Weblogic Server Proxy Plug-in21/7/20265/8/2026
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…
AplazadaAlta (8.7)0.37%—Getgrav Grav-plugin-apiAI21/7/202623/7/2026
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every…
AnalizadaAlta (7.1)0.21%—Verygoodplugins Whatsapp MCP Server20/7/202618/8/2026
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute…
AplazadaMedia (5.4)0.14%💥 PoCWp-feedstats Wordpress PluginAI20/7/202620/7/2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's…
AplazadaAlta (8.2)0.38%—Dancer Plugin Auth GoogleAI17/7/202611/8/2026
Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token…
AplazadaAlta (7.1)0.34%—Getgrav Grav-plugin-apiAI17/7/202617/7/2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accepts credentials via the Authorization and X-API-Token headers (set…
AplazadaAlta (8.2)0.43%—Getgrav Grav-plugin-apiAI17/7/202623/7/2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server access logs, leaked via the Referer header,…
AplazadaBaja (2.3)0.14%—Getgrav Grav-plugin-loginAI17/7/202617/7/2026
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce or Origin/Referer check. Because Grav core dispatches the task from…
AplazadaAlta (8.7)0.44%—Getgrav Grav-plugin-apiAI17/7/202617/7/2026
grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from super-admin users to achieve full instance…
AplazadaAlta (8.6)0.39%—Getgrav Grav-plugin-apiAI17/7/202621/7/2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owning user's full account object, so a key created with limited scopes…
Pendiente de análisisCrítica (9.3)0.88%—Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI16/7/202616/7/2026
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn…
AplazadaMedia (5.4)0.14%—Appointment Booking PluginAI16/7/202616/7/2026
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,…
AplazadaMedia (4.9)0.44%—Cleverplugins SEO BoosterAI16/7/202617/7/2026
The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AplazadaMedia (4.9)0.44%—Cleverplugins SEO BoosterAI16/7/202616/7/2026
The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AplazadaMedia (4.3)0.19%—Pluginops Landing Page BuilderAI16/7/202617/7/2026
The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible…
AplazadaMedia (6.7)0.72%—Nocobase Plugin BackupsAI15/7/202618/7/2026
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command strings executed with Node.js…
AplazadaMedia (6.8)0.47%—NocobaseAINocobase Plugin Collection SQLAI15/7/202616/7/2026
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that…