Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 15% | 💥 Exploit | Mooveagency Import XML AND RSS Feeds | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action. | |
| Modificada | Crítica (9.1) | 1.6% | — | Xylusthemes WP Smart Import | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field. | |
| Modificada | Media (4.3) | 0.76% | — | Mendix Excel Importer | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework. | |
| Modificada | Alta (7.2) | 1.8% | — | College Publisher Import Project College Publisher Import | 6/5/2021 | 17/6/2026 | The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack. | |
| Modificada | Alta (8.8) | 0.65% | — | Themegrill Demo Importer | 5/5/2021 | 17/6/2026 | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. | |
| Modificada | Crítica (9.1) | 4.1% | 💥 Exploit | Themegrill Demo Importer | 5/5/2021 | 17/6/2026 | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | |
| Modificada | Alta (8) | 1.8% | — | Codection Import AND Export Users AND Customers | 4/11/2020 | 17/6/2026 | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. | |
| Modificada | Alta (8.8) | 1.7% | — | Webtoffee Import Export Wordpress Users | 23/4/2020 | 17/6/2026 | The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV. | |
| Modificada | Alta (8.8) | 1.6% | — | Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive | 23/4/2020 | 17/6/2026 | The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests. | |
| Modificada | Crítica (9.8) | 1.4% | — | Fordnn Usersexportimport | 21/1/2020 | 17/6/2026 | The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Import Legacy Media Project Import Legacy Media | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php. | |
| Modificada | Alta (8.2) | 0.59% | — | Jenkins Spira Importer | 17/12/2019 | 17/6/2026 | Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM. | |
| Modificada | Media (5.5) | 0.32% | — | Jenkins Spira Importer | 21/11/2019 | 17/6/2026 | Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (7.3) | 5.1% | 💥 Exploit | Webtoffee Import Export Wordpress Users | 23/8/2019 | 17/6/2026 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class. | |
| Modificada | Alta (8.8) | 0.69% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.93% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. | |
| Modificada | Alta (7.5) | 2.3% | — | Codection Import Users From CSV With Meta | 22/8/2019 | 17/6/2026 | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. | |
| Modificada | Media (6.1) | 0.91% | — | Soflyy WP ALL Import | 20/8/2019 | 17/6/2026 | The wp-all-import plugin before 3.4.7 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Soflyy WP ALL Import | 20/8/2019 | 17/6/2026 | The wp-all-import plugin before 3.4.6 for WordPress has XSS. | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Soflyy WP ALL Import | 20/8/2019 | 17/6/2026 | The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit. | |
| Modificada | Crítica (9.8) | 1.8% | — | Soflyy WP ALL Import | 20/8/2019 | 17/6/2026 | The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. | |
| Modificada | Media (6.1) | 0.91% | — | Soflyy WP ALL Import | 20/8/2019 | 17/6/2026 | The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS. | |
| Modificada | Alta (8.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 14/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.96% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 12/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. |