Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Webhammer WP Custom Fields Search | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Custom Field Suite Project Custom Field Suite | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions. | |
| Modificada | Media (4.8) | 0.46% | — | Themeisle Product Addons & Fields FOR Woocommerce | 15/5/2023 | 17/6/2026 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite… | |
| Modificada | Media (6.1) | 38% | 💥 Exploit | Advancedcustomfields Advanced Custom Fields | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Pixelgrade Pixfields | 9/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Advancedcustomfields Advanced Custom Fields | 2/5/2023 | 17/6/2026 | The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Alta (7.2) | 0.91% | — | WC Fields Factory Project WC Fields Factory | 17/4/2023 | 17/6/2026 | The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Media (6.5) | 0.61% | — | Teclib-edition Fields | 5/4/2023 | 17/6/2026 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check allows any authenticated user to write data to any fields container, including those to which they have no configured access. Versions 1.13.1 and 1.20.4 contain a patch… | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Najeebmedia Woocommerce Checkout Field Manager | 6/3/2023 | 17/6/2026 | The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server | |
| Modificada | Media (4.3) | 0.21% | — | Intel Field Programmable Gate Array Crypto Service Server | 16/2/2023 | 17/6/2026 | Uncaught exception in the FCS Server software maintained by Intel before version 1.1.79.3 may allow a privileged user to potentially enable denial of service via physical access. | |
| Modificada | Alta (7.5) | 0.91% | — | Protocol Go-bitfield | 9/2/2023 | 17/6/2026 | go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user input into the size parameter of `NewBitfield` and `FromBytes` functions, an attacker can trigger `panic`s. This happen when the `size` is a not a multiple of `8` or is… | |
| Modificada | Media (5.4) | 0.55% | — | Paidmembershipspro Custom User Profile Fields FOR User Registration | 30/1/2023 | 17/6/2026 | The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against… | |
| Modificada | Media (5.4) | 0.84% | 💥 Exploit | Panda Pods Repeater Field Project Panda Pods Repeater Field | 30/1/2023 | 17/6/2026 | The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission. | |
| Modificada | Alta (7.5) | 0.52% | — | Oracle Mobile Field Service | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Field Service. Successful… | |
| Modificada | Media (4.8) | 0.47% | — | Cozmoslabs Custom Post Types AND Custom Fields Creator | 16/1/2023 | 17/6/2026 | The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Alta (7.2) | 18% | — | Wpgogo Custom Field Template | 2/1/2023 | 17/6/2026 | The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Iws-geo-form-fields Project Iws-geo-form-fields | 26/12/2022 | 17/6/2026 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. | |
| Modificada | Media (6.1) | 0.49% | — | Ndk-design Ndkadvancedcustomizationfields | 21/12/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter. | |
| Modificada | Alta (7.2) | 1.2% | — | Themehigh Checkout Field Editor FOR Woocommerce | 28/11/2022 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | |
| Modificada | Crítica (9.1) | 0.85% | — | Ndk-design Ndkadvancedcustomizationfields | 22/11/2022 | 9/7/2026 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. | |
| Modificada | Media (6.1) | 0.52% | — | Ndk-design Ndkadvancedcustomizationfields | 2/11/2022 | 9/7/2026 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php. | |
| Modificada | Alta (7.5) | 0.99% | — | Ndk-design Ndkadvancedcustomizationfields | 1/11/2022 | 9/7/2026 | A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | |
| Modificada | Alta (8.8) | 1.6% | — | Advancedcustomfields Advanced Custom Fields | 22/8/2022 | 17/6/2026 | The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite… |