Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)2.7%💥 ExploitResponsive Cookie Consent Project Responsive Cookie Consent24/4/201817/6/2026
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
ModificadaCrítica (9.8)50%💥 ExploitResponsive Mega Menu PRO Project Responsive Mega Menu PROPrestashop28/3/201817/6/2026
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
ModificadaCrítica (9.8)2.1%—Wpsupportplus WP Support Plus Responsive Ticket System14/3/201817/6/2026
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This…
ModificadaCrítica (9.8)19%💥 ExploitQuanticalabs Timetable Responsive Schedule17/2/201817/6/2026
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
ModificadaMedia (5.4)0.56%—Multireligion Responsive Matrimonial Project Multireligion Responsive Matrimonial12/2/201817/6/2026
Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php bg_color parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_height parameter.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php social_icon_1 parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php button_text_link parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title parameter.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter.
ModificadaMedia (4.8)0.62%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_sub_title parameter.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_title parameter.
ModificadaAlta (8.8)0.64%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.
ModificadaMedia (4.8)0.71%—Responsive Coming Soon Page Project Responsive Coming Soon Page13/1/201817/6/2026
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title_icon parameter.
ModificadaMedia (5.4)0.60%—Wpshopmart Tabs Responsive9/1/201817/6/2026
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
ModificadaMedia (4.8)0.49%—Responsive Realestate Script Project Responsive Realestate Script27/12/201717/6/2026
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
ModificadaAlta (8.8)0.46%—Responsive Realestate Script Project Responsive Realestate Script27/12/201717/6/2026
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
ModificadaCrítica (9.8)2.2%💥 ExploitResponsive Events AND Movie Ticket Booking Script Project Responsive Events AND Movie Ticket Booking Script13/12/201717/6/2026
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
ModificadaCrítica (9.8)2.2%💥 ExploitMultireligion Responsive Matrimonial Project Multireligion Responsive Matrimonial13/12/201717/6/2026
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
ModificadaCrítica (9.8)2.2%💥 ExploitResponsive Realestate Script Project Responsive Realestate Script13/12/201717/6/2026
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
ModificadaCrítica (9.8)3.2%—Wpdevart Responsive Image Gallery Gallery Album25/9/201717/6/2026
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
ModificadaCrítica (9.8)2.6%—Rayanehdownload Rk-responsive-contact-form14/9/201717/6/2026
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.
ModificadaMedia (6.1)1.5%—Dfactory Responsive Lightbox7/7/201717/6/2026
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.0%—Wordpress Responsive Preview Project Wordpress Responsive Preview2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in index.php in the WordPress Responsive Preview plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Orbitaley — Vulnerabilidades