Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 2.7% | 💥 Exploit | Responsive Cookie Consent Project Responsive Cookie Consent | 24/4/2018 | 17/6/2026 | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Responsive Mega Menu PRO Project Responsive Mega Menu PROPrestashop | 28/3/2018 | 17/6/2026 | modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter. | |
| Modificada | Crítica (9.8) | 2.1% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 14/3/2018 | 17/6/2026 | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This… | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Quanticalabs Timetable Responsive Schedule | 17/2/2018 | 17/6/2026 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. | |
| Modificada | Media (5.4) | 0.56% | — | Multireligion Responsive Matrimonial Project Multireligion Responsive Matrimonial | 12/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php bg_color parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_height parameter. | |
| Modificada | Media (4.8) | 0.71% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php social_icon_1 parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php button_text_link parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title parameter. | |
| Modificada | Media (4.8) | 0.71% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_sub_title parameter. | |
| Modificada | Media (4.8) | 0.71% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_title parameter. | |
| Modificada | Alta (8.8) | 0.64% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php. | |
| Modificada | Media (4.8) | 0.71% | — | Responsive Coming Soon Page Project Responsive Coming Soon Page | 13/1/2018 | 17/6/2026 | An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title_icon parameter. | |
| Modificada | Media (5.4) | 0.60% | — | Wpshopmart Tabs Responsive | 9/1/2018 | 17/6/2026 | The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php. | |
| Modificada | Media (4.8) | 0.49% | — | Responsive Realestate Script Project Responsive Realestate Script | 27/12/2017 | 17/6/2026 | PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter. | |
| Modificada | Alta (8.8) | 0.46% | — | Responsive Realestate Script Project Responsive Realestate Script | 27/12/2017 | 17/6/2026 | PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Responsive Events AND Movie Ticket Booking Script Project Responsive Events AND Movie Ticket Booking Script | 13/12/2017 | 17/6/2026 | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Multireligion Responsive Matrimonial Project Multireligion Responsive Matrimonial | 13/12/2017 | 17/6/2026 | Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Responsive Realestate Script Project Responsive Realestate Script | 13/12/2017 | 17/6/2026 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | |
| Modificada | Crítica (9.8) | 3.2% | — | Wpdevart Responsive Image Gallery Gallery Album | 25/9/2017 | 17/6/2026 | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php. | |
| Modificada | Crítica (9.8) | 2.6% | — | Rayanehdownload Rk-responsive-contact-form | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php. | |
| Modificada | Media (6.1) | 1.5% | — | Dfactory Responsive Lightbox | 7/7/2017 | 17/6/2026 | Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Wordpress Responsive Preview Project Wordpress Responsive Preview | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the WordPress Responsive Preview plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter. |