Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Pressgrid - Frontend Publish Reaction & Multimedia ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3.1. | |
| Analizada | Alta (7.8) | 0.32% | — | Action1 Agent | 6/6/2025 | 17/6/2026 | Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Action1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Aplazada | Media (4.3) | 0.14% | — | Wpmapplugins Interactive Regional MAP OF AfricaAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-africa allows Cross Site Request Forgery.This issue affects Interactive Regional Map of Africa: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Wpmapplugins Interactive UK Regional MAPAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-map allows Cross Site Request Forgery.This issue affects Interactive UK Regional Map: from n/a through <= 2.0. | |
| Aplazada | Media (5.3) | 0.26% | — | Interactive Regional MAP OF FloridaAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida interactive-map-of-florida allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Interactive Regional Map of Florida: from n/a through <= 1.0. | |
| Aplazada | Media (5.4) | 0.32% | — | Buddydev Activity Plus ReloadedAIBuddypressAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2. | |
| Analizada | Media (5.3) | 0.33% | — | Syntacticsinc Easync | 31/5/2025 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.21 via the 'view_request_details' due to missing validation on a user controlled key. This makes it possible for… | |
| Analizada | Media (6.1) | 0.24% | — | Bestpractical Request Tracker | 28/5/2025 | 17/6/2026 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. | |
| Analizada | Media (6.1) | 0.24% | — | Bestpractical Request Tracker | 28/5/2025 | 17/6/2026 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. | |
| Modificada | Media (6.1) | 0.31% | — | Bestpractical Request Tracker | 28/5/2025 | 17/6/2026 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL. | |
| Aplazada | Media (5.5) | 0.17% | — | Apache Activemq ArtemisAIActivemq Artemis OperatorAI | 26/5/2025 | 17/6/2026 | A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies. | |
| Modificada | Crítica (9.8) | 0.71% | — | Qodeinteractive Wilmer | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.4.2. | |
| Modificada | Alta (8.1) | 0.78% | — | Qodeinteractive Backpack Traveler | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows PHP Local File Inclusion.This issue affects Backpack Traveler: from n/a through <= 2.10.2. | |
| Aplazada | Alta (7) | 0.36% | — | Tibco Activematrix AdministratorAI | 21/5/2025 | 17/6/2026 | Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application. | |
| Modificada | Alta (8.1) | 0.73% | — | Qodeinteractive Foton | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Foton foton allows PHP Local File Inclusion.This issue affects Foton: from n/a through <= 2.5.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Pluginus Active Products Tables FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Stored XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.6.8. | |
| Modificada | Media (5.4) | 0.24% | — | Qodeinteractive QI Blocks | 19/5/2025 | 17/6/2026 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.24% | — | Qodeinteractive QI Blocks | 19/5/2025 | 17/6/2026 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.28% | — | Qodeinteractive QI Blocks | 19/5/2025 | 17/6/2026 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 1.1% | 💥 PoC | Synology Active Backup FOR Microsoft 365 | 16/5/2025 | 17/6/2026 | A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (6.5) | 0.19% | — | Syntacticsinc Easync | 15/5/2025 | 17/6/2026 | The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack | |
| Modificada | Media (5.3) | 0.36% | — | Mooveagency User Activity Tracking AND LOG | 15/5/2025 | 17/6/2026 | This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. | |
| Modificada | Alta (8.8) | 0.68% | — | Dev4press Coreactivity | 15/5/2025 | 17/6/2026 | The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin | |
| Analizada | Media (5.4) | 0.84% | 💥 Exploit | Deryckoe Logdash Activity LOG | 15/5/2025 | 17/6/2026 | The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based… | |
| Modificada | Crítica (9.8) | 0.30% | — | Wbcomdesigns Activity Link Preview FOR Buddypress | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddypress allows Server Side Request Forgery.This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through <= 1.4.4. |