Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
2505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.22% | — | Mailgun SubscriptionsAI | 12/12/2025 | 7/10/2026 | El plugin Mailgun Subscriptions para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del shortcode 'mailgun_subscription_form' del plugin en todas las versiones hasta la 1.3.1, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en los atributos proporcionados por el… | |
| Analizada | Media (5.3) | 0.80% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/12/2025 | 17/6/2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/12/2025 | 17/6/2026 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.3) | 0.25% | — | Scriptsbundle AdforestAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en scriptsbundle AdForest adforest permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a AdForest: desde n/a hasta menor o igual que 6.0.11. | |
| Aplazada | Media (6.1) | 0.26% | — | TwitscriptionAI | 5/12/2025 | 17/6/2026 | The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Alta (7.6) | 0.51% | — | Lfprojects MCP Typescript SDK | 2/12/2025 | 17/6/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with… | |
| Aplazada | Media (5.1) | 0.34% | — | Sentry JavascriptAI | 25/11/2025 | 17/6/2026 | Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js application using the Sentry SDK has sendDefaultPii: true it is possible to inadvertently send certain sensitive HTTP headers, including the Cookie header, to Sentry. Those headers would be stored within… | |
| Aplazada | Media (5.3) | 0.17% | — | Subscriptions Memberships FOR PaypalAI | 22/11/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries… | |
| Aplazada | Media (5.3) | 0.22% | — | Scott Paterson Subscriptions AND Memberships FOR PaypalAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | |
| Analizada | Alta (7.3) | 0.45% | — | Silentmatt Javascript Expression Evaluator | 14/11/2025 | 7/10/2026 | El paquete npm 'expr-eval' es vulnerable a la Contaminación de Prototipos. Un atacante con acceso a la interfaz de evaluación de expresiones puede usar el modelo de herencia basado en prototipos de JavaScript para lograr la ejecución de código arbitrario. El paquete npm 'expr-eval-fork' resuelve este problema. | |
| Analizada | Alta (8.8) | 0.25% | 💥 PoC | Salmen Simple Faucet Script | 12/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing attackers to execute arbitrary code. | |
| Aplazada | Alta (7.2) | 0.36% | — | Easy Email SubscriptionAI | 12/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.4) | 0.19% | — | HT ScriptAI | 8/11/2025 | 7/10/2026 | El plugin Insert Headers and Footers Code - HT Script para WordPress es vulnerable a cross-site scripting almacenado mediante la adición de scripts en todas las versiones hasta la 1.1.6, inclusive, debido a controles de capacidad insuficientes. Esto permite a atacantes autenticados, con acceso de nivel Autor y… | |
| Aplazada | Media (4.3) | 0.13% | — | Easy Email SubscriptionAI | 6/11/2025 | 7/10/2026 | El plugin Easy Email Subscription para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.3, inclusive. Esto se debe a la validación de nonce faltante o incorrecta en la función show_editsub_page(). Esto hace posible que atacantes no autenticados eliminen… | |
| Aplazada | Media (4.9) | 0.30% | — | Easy Email SubscriptionAI | 6/11/2025 | 7/10/2026 | El plugin Easy Email Subscription para WordPress es vulnerable a inyección SQL a través del parámetro 'uid' en todas las versiones hasta la 1.3, inclusive, debido a un escape insuficiente en el parámetro proporcionado por el usuario y la falta de preparación suficiente en la consulta SQL existente. Esto hace posible… | |
| Aplazada | Media (5.3) | 0.23% | — | Cozmoslabs Paid Membership SubscriptionsAI | 5/11/2025 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment() function in all versions up to, and… | |
| Analizada | Crítica (9.8) | 1.8% | 💥 PoC | Jorenbroekema Javascript Expression EvaluatorSilentmatt Javascript Expression Evaluator | 5/11/2025 | 17/6/2026 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and… | |
| Analizada | Alta (8.5) | 0.21% | — | HP Client Management Script Library | 3/11/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability. | |
| Aplazada | Media (4.4) | 0.19% | — | CSS Javascript ToolboxAI | 1/11/2025 | 17/6/2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 12.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Alta (7.5) | 0.34% | — | Scriptsbundle AdforestAI | 30/10/2025 | 17/6/2026 | AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization credential, which can be manipulated by… | |
| Aplazada | Media (4.3) | 0.25% | — | Joby Joseph SEO Meta Description UpdaterAI | 27/10/2025 | 8/10/2026 | Vulnerabilidad de autorización faltante en Joby Joseph SEO Meta Description Updater seo-meta-description-updater permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a SEO Meta Description Updater: desde n/a hasta menor o igual que 1.2.0. | |
| Aplazada | Media (5.9) | 0.29% | — | I13websolution Email Subscription PopupAI | 22/10/2025 | 8/10/2026 | Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Nks Email Subscription Popup email-subscribe permite XSS Almacenado. Este problema afecta a Email Subscription Popup: desde n/a hasta menor o igual que 1.2.26. | |
| Aplazada | Alta (8.8) | 0.63% | — | Phpscriptpoint InsuranceAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de deserialización de datos no confiables en designthemes Insurance insurance permite la inyección de objetos. Este problema afecta a Insurance: desde n/a hasta menor o igual que 3.5. | |
| Analizada | Media (6.1) | 0.23% | — | Oracle Scripting | 21/10/2025 | 8/10/2026 | Vulnerabilidad en el producto Oracle Scripting de Oracle E-Business Suite (componente: Misceláneo). Versiones compatibles que están afectadas son 12.2.3-12.2.14. Vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso de red vía HTTP comprometer Oracle Scripting. Ataques exitosos requieren… | |
| Aplazada | Media (6.4) | 0.26% | — | Async JavascriptAI | 18/10/2025 | 17/6/2026 | The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization checks on the aj_steps AJAX aciton along with a lack on sanitization on the settings saved via the function. This makes it possible for authenticated… |