Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2440 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 0.64% | — | Appium/storage-plugin | 8/7/2026 | 26/8/2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path… | |
| Aplazada | Media (5.3) | 0.44% | — | Getgrav Grav-plugin-apiAIGetgrav GravAI | 8/7/2026 | 8/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType) beginning with 'image/' and does not inspect the actual file content or… | |
| Aplazada | Alta (8.1) | 0.65% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 8/7/2026 | 8/7/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to… | |
| Aplazada | Alta (8.8) | 1.0% | — | I-plugins Whmcs BridgeAI | 8/7/2026 | 8/7/2026 | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's… | |
| Aplazada | Alta (8.8) | 0.51% | — | Simple-membership-plugin Simple MembershipAI | 6/7/2026 | 6/7/2026 | The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in… | |
| Aplazada | Alta (8.1) | 0.25% | — | Dancer2 Plugin Auth Oauth ProviderAI | 4/7/2026 | 6/7/2026 | Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpsc-plugin Structured ContentAI | 2/7/2026 | 2/7/2026 | Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Plugins WP DebuggingAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions. | |
| Aplazada | Alta (8.3) | 0.40% | — | Geovision WEB PluginAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (7.5) | 0.49% | — | Gazebo PluginsAI | 1/7/2026 | 2/7/2026 | An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted geometry_msgs::Twist message. | |
| Aplazada | Media (4.2) | 0.22% | — | Plugin-planet User Submitted PostsAI | 1/7/2026 | 1/7/2026 | The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled. | |
| Aplazada | Media (4.3) | 0.15% | — | IO Technologies Plugin FOR Google AnalyticsAI | 30/6/2026 | 30/6/2026 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Media (4.4) | 0.34% | — | Team Members Multi Language Supported Team PluginAI | 30/6/2026 | 30/6/2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (7.1) | 0.25% | — | Pluginops Landing Page BuilderAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | |
| Aplazada | Baja (1.1) | 0.11% | — | Antlr4AIAntlr4-maven-pluginAI | 28/6/2026 | 29/6/2026 | A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local… | |
| Aplazada | Alta (8.1) | 0.38% | — | Paid Membership PluginAI | 27/6/2026 | 29/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active… | |
| Aplazada | Media (5.3) | 0.31% | — | Gravityplugins GravityviewAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant MenuAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | |
| Pendiente de análisis | Media (4.8) | 0.38% | — | Rapid7 Insightconnect Markdown PluginAI | 26/6/2026 | 24/7/2026 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial… | |
| Aplazada | Alta (8.1) | 0.35% | — | Royal Plugins Royal MCPAI | 25/6/2026 | 25/6/2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. | |
| Aplazada | Alta (8.8) | 0.83% | — | Jenkins External Workspace Manager PluginAI | 24/6/2026 | 25/6/2026 | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code… | |
| Aplazada | Media (4.3) | 0.27% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Media (5.4) | 0.14% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method. | |
| Aplazada | Media (5.4) | 0.23% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method. |