Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

401 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.60%—Mekshq Meks Easy Photo Feed Widget14/3/202217/6/2026
The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings. As a result, any authenticated user, such as subscriber could update the plugin's…
ModificadaAlta (7.5)0.96%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
ModificadaMedia (6.5)0.83%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
ModificadaMedia (5.4)0.65%—Adtribes Product Feed PRO FOR Woocommerce7/3/202217/6/2026
The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting
ModificadaAlta (7.2)1.3%—Wpaffiliatefeed Tradetracker-store7/3/202217/6/2026
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
ModificadaAlta (7.2)1.3%—Exportfeed21/2/202217/6/2026
The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using it in a SQL statement, leading to a SQL injection vulnerability exploitable by high privilege users
ModificadaMedia (6.1)2.0%💥 ExploitFeedwordpress Project Feedwordpress21/2/202217/6/2026
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (5.4)0.61%—Adtribes Product Feed PRO FOR Woocommerce24/1/202217/6/2026
The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.
ModificadaMedia (5.4)1.0%💥 ExploitSmashballoon Smash Balloon Social Post Feed17/1/202217/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
ModificadaMedia (5.4)0.68%—Smashballoon Smash Balloon Social Post Feed29/11/202117/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.
ModificadaAlta (7.5)1.3%—Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+310/11/202117/6/2026
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
ModificadaAlta (7.5)1.3%—Softing Datafeed OPC SuiteSofting OPCSofting Secure Integration ServerSofting TH Scope10/11/202117/6/2026
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a OPC/UA client. The client process may crash unexpectedly because of a wrong type cast, and must be restarted.
ModificadaMedia (4.8)0.64%—Etruel Wpematico RSS Feed Fetcher1/11/202117/6/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.4)0.65%—Bplugins Easy Twitter Feed18/10/202117/6/2026
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
ModificadaAlta (7.2)1.5%—DPL Product Feed ON Woocommerce20/9/202117/6/2026
The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
ModificadaMedia (6.1)1.3%—Smashballoon Smash Balloon Social Post Feed13/9/202117/6/2026
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored…
ModificadaMedia (6.1)0.90%—Feedify WEB Push Notifications10/9/202117/6/2026
The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.
ModificadaAlta (8.8)0.68%—Youtube Feeder Project Youtube Feeder5/8/202117/6/2026
The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.
ModificadaCrítica (9.1)15%💥 ExploitMooveagency Import XML AND RSS Feeds7/7/202117/6/2026
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
ModificadaMedia (6.1)0.85%—Ougc Feedback Project Ougc Feedback9/3/202117/6/2026
The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.
ModificadaMedia (6.1)0.87%—RSS Feed Widget Project RSS Feed Widget26/8/202017/6/2026
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
ModificadaAlta (7.5)2.2%—Feedgen Project Feedgen28/1/202017/6/2026
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tree. During this process, feedgen is vulnerable to XML Denial of Service Attacks…
ModificadaMedia (6.1)1.2%—Winwar WP Ebay Product Feeds27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.
ModificadaAlta (8.8)0.85%—Tipsandtricks-hq Category Specific RSS Feed Subscription12/9/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.