Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.71% | — | Weblizar Social Likebox & Feed | 29/8/2019 | 17/6/2026 | The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. | |
| Modificada | Alta (8.8) | 0.69% | — | Quadlayers WP Social Feed Gallery | 29/8/2019 | 17/6/2026 | The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. | |
| Modificada | Media (6.1) | 0.92% | — | Feedwordpress Project Feedwordpress | 28/8/2019 | 17/6/2026 | The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Crítica (9.8) | 2.8% | — | Slickremix Feed Them Social | 27/8/2019 | 17/6/2026 | The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button. | |
| Modificada | Media (6.1) | 0.91% | — | Slickremix Feed Them Social | 27/8/2019 | 17/6/2026 | The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button. | |
| Modificada | Media (5.4) | 3.2% | 💥 Exploit | Webappick Woocommerce Product Feed | 23/7/2019 | 17/6/2026 | WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in. | |
| Modificada | Media (6.1) | 1.2% | — | Feed Statistics Project Feed Statistics | 16/9/2018 | 17/6/2026 | The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. | |
| Modificada | Media (6.1) | 0.94% | — | Web-dorado WD Instagram Feed | 23/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post. | |
| Modificada | Media (6.1) | 0.94% | — | Web-dorado WD Instagram Feed | 23/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio. | |
| Modificada | Alta (8.8) | 0.60% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php. | |
| Modificada | Media (6.1) | 0.78% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Hotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script | 13/12/2017 | 17/6/2026 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Media (4.8) | 1.0% | — | Ultimate Instagram Feed Project Ultimate Instagram Feed | 9/11/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter. | |
| Modificada | Media (6.5) | 0.89% | — | Redhat Feedhenry Enterprise Mobile Application Platform | 20/9/2017 | 17/6/2026 | Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. | |
| Modificada | Crítica (9.8) | 1.3% | — | GE Multilin SR 750 Feeder Protection Relay FirmwareGE Multilin SR 760 Feeder Protection Relay FirmwareGE Multilin SR 469 Motor Protection Relay FirmwareMultilin SR 489 Generator Protection Relay Firmware+6 | 30/6/2017 | 17/6/2026 | A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489… | |
| Modificada | Alta (8.8) | 1.6% | — | Multi Feed Reader Project Multi Feed Reader | 9/6/2017 | 17/6/2026 | SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.6) | 0.75% | — | Zendesk Feedback TAB | 11/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 3.7% | 💥 Exploit | Feedwordpress Project Feedwordpress | 21/5/2015 | 17/6/2026 | SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php. | |
| Modificada | Media (6.8) | 1.2% | — | Bird Feeder Project Bird Feeder | 24/12/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) user or (2) password parameter in the bird-feeder page to… | |
| Modificada | Baja (2.1) | 0.73% | — | Feed Element Mapper Project Feed Element Mapper | 13/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options. | |
| Modificada | Alta (7.5) | 1.2% | — | Christophe Balisky Meta Feedit | 25/6/2013 | 16/6/2026 | SQL injection vulnerability in the meta_feedit extension 0.1.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.6% | — | Feedweb | 31/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Feeds Project Feeds | 3/12/2012 | 16/6/2026 | The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed. |