Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.27% | — | Tipsandtricks-hq Category Specific RSS Feed Subscription | 3/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Pixelyoursite Product Catalog Feed | 2/5/2023 | 17/6/2026 | The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.52% | — | Pixelyoursite Product Catalog Feed | 2/5/2023 | 17/6/2026 | The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators. | |
| Modificada | Crítica (9.8) | 0.75% | — | Shoppingfeed | 18/4/2023 | 17/6/2026 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There… | |
| Modificada | Alta (8.8) | 0.25% | — | Adtribes Product Feed PRO FOR Woocommerce | 6/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Winwar WP Ebay Product Feeds | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP eBay Product Feeds plugin <= 3.3.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wp-master Feed Changer & Remover | 20/3/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions. | |
| Modificada | Alta (8.8) | 1.2% | — | Tenable NessusTenable Plugin Feed | 15/3/2023 | 17/6/2026 | A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets. | |
| Modificada | Media (4.3) | 0.51% | — | THM Feedbacksystem | 7/3/2023 | 17/6/2026 | thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to associate the subresults with a specific… | |
| Modificada | Media (5.4) | 0.53% | — | Rebelcode Spotlight Social Feeds | 13/2/2023 | 17/6/2026 | The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (5.4) | 0.51% | — | Themeisle RSS Aggregator BY Feedzy | 30/1/2023 | 17/6/2026 | The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.47% | — | Easysocialfeed Easy Social Feed | 23/1/2023 | 17/6/2026 | The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.51% | — | Smashballoon Smash Balloon Social Post Feed | 16/1/2023 | 17/6/2026 | The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | |
| Modificada | Crítica (9.8) | 0.66% | — | Lolfeedback Project Lolfeedback | 15/1/2023 | 17/6/2026 | A vulnerability has been found in lolfeedback and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The identifier of the patch is 6cf0b5f2228cd8765f734badd37910051000f2b2. It is recommended to apply a patch to fix this issue. The identifier… | |
| Modificada | Media (5.4) | 0.55% | — | Jenkins Extreme-feedback | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps. | |
| Modificada | Alta (8) | 0.34% | — | Access Code Feeder Project Access Code Feeder | 9/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress. | |
| Modificada | Media (6.1) | 0.77% | — | Slickremix Feed Them Social | 22/8/2022 | 17/6/2026 | The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 6.5% | 💥 Exploit | Slickremix Feed Them Social | 22/8/2022 | 17/6/2026 | The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 1.7% | — | Slickremix Feed Them Social | 18/7/2022 | 17/6/2026 | The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data… | |
| Modificada | Media (5.4) | 0.73% | — | Awin Data Feed | 11/7/2022 | 17/6/2026 | The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Awin Data Feed | 11/7/2022 | 17/6/2026 | The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Extreme Feedback Panel | 30/6/2022 | 17/6/2026 | Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Easysocialfeed Easy Social Feed | 18/4/2022 | 17/6/2026 | The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (7.2) | 1.3% | — | DPL Sync Woocommerce Product Feed TO Google Shopping | 28/3/2022 | 17/6/2026 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard | |
| Modificada | Crítica (9.8) | 2.8% | — | Gnome Ocrfeeder | 24/3/2022 | 17/6/2026 | GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename. |