Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.23% | — | Pencidesign Penci ReviewAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Review penci-review allows Stored XSS.This issue affects Penci Review: from n/a through <= 3.5. | |
| Aplazada | Media (4.3) | 0.26% | — | Topdevs Smart Product ViewerAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in topdevs Smart Product Viewer smart-product-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Product Viewer: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.3) | 0.31% | — | Ryviu Product Reviews FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ryviu Ryviu – Product Reviews for WooCommerce ryviu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ryviu – Product Reviews for WooCommerce: from n/a through <= 3.1.26. | |
| Aplazada | Media (6.5) | 0.15% | — | Thimpress Learnpress - Course ReviewAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress – Course Review learnpress-course-review allows Stored XSS.This issue affects LearnPress – Course Review: from n/a through <= 4.1.9. | |
| Aplazada | Alta (7.1) | 0.26% | — | Cridiostudio Listingpro ReviewsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro Reviews listingpro-reviews allows Reflected XSS.This issue affects ListingPro Reviews: from n/a through < 2.9.11. | |
| Aplazada | Media (4.9) | 0.22% | — | Marcomilesi Anac XML ViewerAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Request Forgery.This issue affects ANAC XML Viewer: from n/a through <= 1.8.2. | |
| Analizada | Alta (8.4) | 0.17% | — | Dlink D-view 8 | 21/1/2026 | 17/6/2026 | D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the… | |
| Analizada | Alta (8.7) | 0.38% | — | Dlink D-view 8 | 21/1/2026 | 17/6/2026 | D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be… | |
| Aplazada | Alta (8.4) | 0.16% | — | Fsas Technologies Serverview Agents FOR WindowsAI | 21/1/2026 | 17/6/2026 | The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be executed with the administrator privilege when the installer is executed. | |
| Analizada | Crítica (9.8) | 1.5% | — | Deltaww Diaview | 16/1/2026 | 17/6/2026 | Delta Electronics DIAView has Command Injection vulnerability. | |
| Modificada | Crítica (9.8) | 0.54% | — | Deltaww Diaview | 16/1/2026 | 17/6/2026 | Delta Electronics DIAView has multiple vulnerabilities. | |
| Modificada | Crítica (9.8) | 0.58% | — | Deltaww Diaview | 16/1/2026 | 17/6/2026 | Delta Electronics DIAView has multiple vulnerabilities. | |
| Aplazada | Media (6.4) | 0.22% | — | Nearby NOW ReviewsAI | 9/1/2026 | 17/6/2026 | The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.22% | — | Entry ViewsAI | 9/1/2026 | 17/6/2026 | The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.22% | — | Agenceseo WP Google Street ViewAI | 9/1/2026 | 17/6/2026 | The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpgsv_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.1) | 0.36% | — | Starred ReviewAI | 7/1/2026 | 17/6/2026 | The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.5) | 0.42% | — | ReviewifyAI | 7/1/2026 | 17/6/2026 | The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'send_test_email' AJAX action in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to create arbitrary… | |
| Aplazada | Media (6.4) | 0.27% | — | Cusrev Customer Reviews FOR WoocommerceAI | 7/1/2026 | 7/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access… | |
| Aplazada | Media (4.3) | 0.18% | — | BBR Plugins Better Business ReviewsAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Media (5.3) | 0.21% | — | Woo-reviews-by-wiremoAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Wiremo Wiremo woo-reviews-by-wiremo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wiremo: from n/a through <= 1.4.99. | |
| Aplazada | Baja (2) | 0.22% | — | Sunhailin12315 Product-reviewAI | 30/12/2025 | 17/6/2026 | A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb4639. This affects an unknown part of the component Write a Review. Performing manipulation of the argument content results in cross site scripting. The attack is possible to be carried out remotely.… | |
| Aplazada | Alta (7.1) | 0.43% | — | Novarad Novapacs Diagnostics ViewerAI | 24/12/2025 | 17/6/2026 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Aplazada | Media (5.3) | 0.25% | — | Addonify Quick ViewAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.9) | 0.21% | — | Amp-mode Review-disclaimerAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AMP-MODE Review Disclaimer review-disclaimer allows Stored XSS.This issue affects Review Disclaimer: from n/a through <= 2.0.3. | |
| Aplazada | Alta (7.8) | 0.16% | — | Tradingview DesktopAIElectronAI | 23/12/2025 | 17/6/2026 | TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… |