Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 1.1% | — | Microsoft Purview | 19/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.9) | 0.24% | — | Richplugins Rich Showcase FOR Google ReviewsAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue affects Rich Showcase for Google Reviews: from n/a through <= 6.9.4.3. | |
| Aplazada | Media (4.9) | 0.19% | — | Andy Fragen Embed PDF ViewerAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Side Request Forgery.This issue affects Embed PDF Viewer: from n/a through <= 2.4.7. | |
| Aplazada | Media (4.3) | 0.13% | — | Font Pairing Preview FOR Landing PagesAI | 7/3/2026 | 17/6/2026 | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing… | |
| Aplazada | Media (4.8) | 0.41% | — | Dato CMSAIDato WEB PreviewsAI | 27/2/2026 | 17/6/2026 | Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabling the loading of arbitrary external resources or origins. This issue affects Web Previews < v1.0.31. | |
| Aplazada | Media (5.3) | 0.34% | — | Villatheme Woocommerce Photo ReviewsAI | 26/2/2026 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.4.4. | |
| Analizada | Media (5.5) | 0.59% | — | Fabian Online Reviewer System | 22/2/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.8) | 0.30% | — | Santesoft Dicom Viewer PRO | 20/2/2026 | 17/6/2026 | Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.1) | 0.26% | — | Sricam Deviceviewer | 20/2/2026 | 17/6/2026 | Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and… | |
| Analizada | Alta (8.4) | 0.33% | — | Sricam Deviceviewer | 20/2/2026 | 17/6/2026 | Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a… | |
| Aplazada | Media (4.3) | 0.24% | — | Wisernotify Wiser ReviewAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9. | |
| Aplazada | Media (5.4) | 0.29% | — | BBR Plugins Better Business ReviewsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Alta (7.2) | 0.27% | — | Gowebsolutions WP Customer ReviewsAI | 19/2/2026 | 17/6/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (4.6) | 0.34% | — | IsmartviewproAI | 18/2/2026 | 17/6/2026 | iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the camera ID input field. Attackers can paste a 257-character buffer into the camera DID and password fields to trigger an application crash on iOS devices. | |
| Analizada | Alta (8.8) | 0.73% | — | Shd101wyy Markdown Preview Enhanced | 16/2/2026 | 17/6/2026 | An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file. | |
| Aplazada | Alta (8.8) | 0.34% | — | Starfish Review Generation AND MarketingAI | 13/2/2026 | 17/6/2026 | The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, 3.1.19. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.27% | — | Cusrev Customer Reviews FOR WoocommerceAI | 12/2/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests'… | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress Server LOG ViewerAI | 11/2/2026 | 17/6/2026 | WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface. | |
| Analizada | Baja (2) | 0.23% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack… | |
| Analizada | Baja (1.9) | 0.25% | 💥 PoC | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.40% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.40% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection. The attack can be executed remotely. The exploit is publicly… | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.5) | 0.43% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack remotely. The exploit… |