Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Aplazada | Media (5.3) | 1.9% | — | Times Software E-payrollAI | 18/11/2025 | 17/6/2026 | Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an unauthenticated attacker to perform DoS attacks. SQL injection attacks might also be feasible, although so far creating a working exploit has been prevented probably by… | |
| Aplazada | Baja (1.8) | 0.11% | — | Bytecodealliance WasmtimeAI | 12/11/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not… | |
| Aplazada | Media (6.4) | 0.27% | — | Skip TO TimestampAI | 11/11/2025 | 17/6/2026 | The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. This is due to insufficient input sanitization and output escaping on the 'time' attribute. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.22% | — | WP Count Down TimerAI | 11/11/2025 | 30/9/2026 | The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.56% | — | Daman Jeet Real Time Validation FOR Gravity FormsAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validation-for-gravity-forms allows PHP Local File Inclusion.This issue affects Real Time Validation for Gravity Forms: from n/a through… | |
| Aplazada | Media (6.5) | 0.27% | — | Codebangers ALL IN ONE Time Clock LiteAI | 4/11/2025 | 17/6/2026 | The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX actions to unauthenticated users via wp_ajax_nopriv_ hooks, while relying only on a nonce check… | |
| Aplazada | Baja (2.1) | 0.26% | — | Dulaiduwang003 Time-sea-plusAI | 27/10/2025 | 17/6/2026 | A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affects the function alipayIsSucceed of the file PayController.java of the component Order Status Handler. The manipulation leads to improper authorization. Remote exploitation of the attack is possible.… | |
| Aplazada | Crítica (9.1) | 0.33% | — | Etimetype LiteAI | 27/10/2025 | 17/6/2026 | An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations. | |
| Analizada | Baja (2.1) | 0.43% | — | Bytecodealliance Wasmtime | 24/10/2025 | 1/10/2026 | Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert… | |
| Aplazada | Media (6.4) | 0.24% | — | Wpplugin Time ClockAI | 24/10/2025 | 17/6/2026 | The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.3.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.20% | — | Wpclever WPC Countdown TimerAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Countdown Timer for WooCommerce wpc-countdown-timer allows Stored XSS.This issue affects WPC Countdown Timer for WooCommerce: from n/a through <= 3.1.4. | |
| Aplazada | Media (4.3) | 0.19% | — | Codebangers ALL IN ONE Time Clock LiteAI | 22/10/2025 | 17/6/2026 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the 'aio_time_clock_lite_js' AJAX action due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.41% | — | LibretimeAI | 21/10/2025 | 17/6/2026 | LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can access analytics data via the Web UI and direct API calls. The backend does not verify role-based permissions for analytics endpoints, allowing unauthorized retrieval of station-wide metrics. This… | |
| Modificada | Alta (7.1) | 0.38% | — | Microchip Timeprovider 4100 Firmware | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5. | |
| Modificada | Alta (8.9) | 1.4% | — | Microchip Timeprovider 4100 Firmware | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. | |
| Modificada | Alta (8.9) | 1.4% | — | Microchip Timeprovider 4100 Firmware | 20/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. | |
| Analizada | Baja (1) | 0.19% | — | Bytecodealliance Wasmtime | 7/10/2025 | 17/6/2026 | Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development of 37.0.0 and all prior versions of Wasmtime are unaffected. If `anyref` or… | |
| Aplazada | Baja (2.3) | 0.19% | — | Br-automation RuntimeAI | 7/10/2025 | 17/6/2026 | A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions. | |
| Aplazada | Media (5.1) | 0.26% | — | Br-automation Automation RuntimeAI | 7/10/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session | |
| Aplazada | Crítica (9.3) | 0.28% | — | B R Automation RuntimeAI | 7/10/2025 | 17/6/2026 | An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions. | |
| Aplazada | Alta (7.1) | 0.66% | 💥 PoC | Openplc RuntimeAI | 3/10/2025 | 17/6/2026 | OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on… | |
| Analizada | Baja (2.1) | 0.37% | — | Bytecodealliance Webassembly Micro Runtime | 16/9/2025 | 17/6/2026 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first operand (memory address pointer) is greater… | |
| Aplazada | Alta (8.8) | 0.36% | — | Time TrackerAI | 11/9/2025 | 17/6/2026 | The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_function' and 'tt_delete_record_function' functions in all versions up to, and including, 3.1.0. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.24% | — | Flickdevs Countdown Timer FOR ElementorAI | 11/9/2025 | 17/6/2026 | The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_label' Parameter in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… |