Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.78% | — | Duogeek Duofaq-responsive-flat-simple-faq | 14/12/2021 | 17/6/2026 | The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.8. | |
| Modificada | Alta (7.2) | 1.5% | — | Webpsilon Responsive 3D Slider | 20/9/2021 | 17/6/2026 | The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we… | |
| Modificada | Alta (8.8) | 1.4% | — | Ays-pro Portfolio Responsive Gallery | 2/8/2021 | 17/6/2026 | The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before… | |
| Modificada | Crítica (9.8) | 1.9% | — | Responsive Ordering System Project Responsive Ordering System | 23/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload to Product_model.php. | |
| Modificada | Alta (8.8) | 0.80% | — | Expresstech Responsive Menu | 5/4/2021 | 17/6/2026 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the… | |
| Modificada | Alta (8.8) | 1.2% | — | Expresstech Responsive Menu | 5/4/2021 | 17/6/2026 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site. | |
| Modificada | Alta (8.8) | 8.2% | 💥 PoC | Expresstech Responsive Menu | 5/4/2021 | 17/6/2026 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an… | |
| Modificada | Alta (8.8) | 1.6% | — | Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive | 23/4/2020 | 17/6/2026 | The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests. | |
| Modificada | Crítica (9.8) | 3.5% | — | Total-soft Responsive Poll | 13/4/2020 | 17/6/2026 | An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations. | |
| Modificada | Media (6.1) | 0.91% | — | Tecrail Responsive Filemanager | 30/3/2020 | 17/6/2026 | An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a payload in the type parameter, and then… | |
| Modificada | Crítica (9.8) | 20% | 💥 PoC | Tecrail Responsive Filemanager | 14/3/2020 | 17/6/2026 | An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php… | |
| Modificada | Crítica (9.8) | 1.5% | — | Tecrail Responsive Filemanager | 7/3/2020 | 17/6/2026 | upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an… | |
| Modificada | Alta (7.5) | 3.1% | — | Smartit Premium Responsive Project Smartit Premium Responsive | 11/10/2019 | 17/6/2026 | The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Blessing Premium Responsive Project Blessing Premium Responsive | 11/10/2019 | 17/6/2026 | The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Goodnex Premium Responsive Project Goodnex Premium Responsive | 11/10/2019 | 17/6/2026 | The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Almera Responsive Portfolio Site Template Project Almera Responsive Portfolio Site Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Almera Responsive Portfolio Project Almera Responsive Portfolio | 11/10/2019 | 17/6/2026 | The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Axioma Premium Responsive Project Axioma Premium Responsive | 11/10/2019 | 17/6/2026 | The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Accio Responsive Onepage Parallax Site Template Project Accio Responsive Onepage Parallax Site Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Accio ONE Page Parallax Responsive Theme Project Accio ONE Page Parallax Responsive Theme | 11/10/2019 | 17/6/2026 | The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | CAR Dealer / Auto Dealer Responsive Project CAR Dealer / Auto Dealer Responsive | 11/10/2019 | 17/6/2026 | The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Media (6.1) | 0.96% | — | Tonjoostudio Fluid-responsive-slideshow | 17/9/2019 | 17/6/2026 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter. | |
| Modificada | Alta (8.8) | 0.73% | — | Tonjoostudio Fluid-responsive-slideshow | 17/9/2019 | 17/6/2026 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS. | |
| Modificada | Alta (8.8) | 1.9% | — | Jtrt Responsive Tables Project Jtrt Responsive Tables | 10/9/2019 | 17/6/2026 | The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. |