Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 8.6% | 💥 PoC | Sygnoos Popup Builder | 17/2/2020 | 17/6/2026 | The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to… | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Crítica (9.1) | 9.4% | 💥 Exploit | Code-atlantic Popup Maker | 14/10/2019 | 17/6/2026 | An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug… | |
| Modificada | Alta (8.8) | 2.1% | — | Omaksolutions Slick-popup | 3/9/2019 | 17/6/2026 | The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action. | |
| Modificada | Alta (8.8) | 0.68% | — | Supsystic Popup | 20/8/2019 | 17/6/2026 | The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 2.7% | — | Sygnoos Popup Builder | 6/8/2019 | 17/6/2026 | A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled. | |
| Modificada | Media (6.1) | 1.6% | — | Code-atlantic Popup Maker | 2/8/2017 | 17/6/2026 | Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (10) | 7.8% | — | Pharos Popup | 10/3/2017 | 17/6/2026 | A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buffer overflow resulting in potential remote code execution. This client is always listening, has root privileges, and… | |
| Modificada | Crítica (9) | 4.0% | — | Pharos Popup | 10/3/2017 | 17/6/2026 | A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buffer overflow resulting in potential remote code execution. This client is always listening, has root privileges, and… | |
| Modificada | Alta (7.5) | 2.1% | — | Pharos Popup | 10/3/2017 | 17/6/2026 | A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to an out of bounds read causing a crash and a denial of service. | |
| Modificada | Crítica (10) | 5.1% | — | Pharos Popup | 10/3/2017 | 17/6/2026 | An exploitable buffer overflow exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buffer overflow resulting in remote code execution. This client is always listening, has root privileges, and… | |
| Modificada | Media (6.8) | 1.2% | — | Timed Popup Project Timed Popup | 5/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Timed Popup (wp-timed-popup) plugin 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the… | |
| Modificada | Media (4.3) | 1.6% | — | Simple Popup Project Simple Popup | 30/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the z parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | E-topbiz Slide Popups | 24/2/2009 | 16/6/2026 | SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Alta (7.5) | 3.7% | — | Popup Plus Plugin FOR Miranda IM | 2/5/2005 | 16/6/2026 | Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (10) | 9.1% | 💥 Exploit | Linpopup | 10/1/2005 | 16/6/2026 | Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted message that is not properly handled during a Reply operation. | |
| Modificada | Alta (7.2) | 1.0% | 💥 Exploit | Gernot Stocker Kpopup | 31/12/2003 | 16/6/2026 | misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program. | |
| Modificada | Alta (7.2) | 0.55% | — | Gernot Stocker Kpopup | 31/12/2003 | 16/6/2026 | Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments. |