Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

401 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.71%—Weblizar Social Likebox & Feed29/8/201917/6/2026
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
ModificadaAlta (8.8)0.69%—Quadlayers WP Social Feed Gallery29/8/201917/6/2026
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
ModificadaMedia (6.1)0.92%—Feedwordpress Project Feedwordpress28/8/201917/6/2026
The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaCrítica (9.8)2.8%—Slickremix Feed Them Social27/8/201917/6/2026
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
ModificadaMedia (6.1)0.91%—Slickremix Feed Them Social27/8/201917/6/2026
The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
ModificadaMedia (5.4)3.2%💥 ExploitWebappick Woocommerce Product Feed23/7/201917/6/2026
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.
ModificadaMedia (6.1)1.2%—Feed Statistics Project Feed Statistics16/9/201817/6/2026
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
ModificadaMedia (6.1)0.94%—Web-dorado WD Instagram Feed23/4/201817/6/2026
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post.
ModificadaMedia (6.1)0.94%—Web-dorado WD Instagram Feed23/4/201817/6/2026
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio.
ModificadaAlta (8.8)0.60%—Weblizar Pinterest-feeds13/1/201817/6/2026
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.
ModificadaMedia (6.1)0.78%—Weblizar Pinterest-feeds13/1/201817/6/2026
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter.
ModificadaMedia (6.1)0.95%—Weblizar Pinterest-feeds13/1/201817/6/2026
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter.
ModificadaMedia (6.1)0.95%—Weblizar Pinterest-feeds13/1/201817/6/2026
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitHotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script13/12/201717/6/2026
Food Order Script 1.0 has SQL Injection via the /list city parameter.
ModificadaMedia (4.8)1.0%—Ultimate Instagram Feed Project Ultimate Instagram Feed9/11/201717/6/2026
Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter.
ModificadaMedia (6.5)0.89%—Redhat Feedhenry Enterprise Mobile Application Platform20/9/201717/6/2026
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
ModificadaCrítica (9.8)1.3%—GE Multilin SR 750 Feeder Protection Relay FirmwareGE Multilin SR 760 Feeder Protection Relay FirmwareGE Multilin SR 469 Motor Protection Relay FirmwareMultilin SR 489 Generator Protection Relay Firmware+630/6/201717/6/2026
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489…
ModificadaAlta (8.8)1.6%—Multi Feed Reader Project Multi Feed Reader9/6/201717/6/2026
SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (2.6)0.75%—Zendesk Feedback TAB11/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)3.7%💥 ExploitFeedwordpress Project Feedwordpress21/5/201517/6/2026
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.
ModificadaMedia (6.8)1.2%—Bird Feeder Project Bird Feeder24/12/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) user or (2) password parameter in the bird-feeder page to…
ModificadaBaja (2.1)0.73%—Feed Element Mapper Project Feed Element Mapper13/5/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.
ModificadaAlta (7.5)1.2%—Christophe Balisky Meta Feedit25/6/201316/6/2026
SQL injection vulnerability in the meta_feedit extension 0.1.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (3.5)1.6%—Feedweb31/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter.
ModificadaMedia (4.3)1.2%—Feeds Project Feeds3/12/201216/6/2026
The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed.