Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

751 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.32%—Uriahs Victor Location Picker AT Checkout FOR WoocommerceAI26/3/202417/6/2026
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.
AplazadaAlta (8.1)0.73%—Check AND LOG EmailAI26/3/202417/6/2026
The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker…
ModificadaMedia (5.4)0.43%—Themelocation Custom Woocommerce Checkout Fields Editor23/3/202417/6/2026
The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaAlta (7.8)0.18%—Checkmk22/3/202417/6/2026
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
AnalizadaBaja (3.3)0.25%—Checkmk22/3/202417/6/2026
Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.
AnalizadaMedia (6.7)0.20%—Checkmk22/3/202417/6/2026
Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
ModificadaMedia (4.8)0.34%—Wpmudev Broken Link Checker15/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Broken Link Checker allows Stored XSS.This issue affects Broken Link Checker: from n/a through 2.2.3.
AnalizadaAlta (7.8)0.33%💥 PoCCheckmk11/3/202417/6/2026
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
ModificadaMedia (5.4)0.69%—Jenkins Owasp Dependency-check6/3/202417/6/2026
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.
AnalizadaMedia (4.8)0.42%—Josephlopreste Restaurant Solutions - Checklist29/2/202417/6/2026
The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web…
ModificadaCrítica (9.8)0.63%—Sysbasics Easy Checkout Field Editor26/2/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.
AnalizadaAlta (7.8)0.16%—Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+1214/2/202417/6/2026
Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6)0.17%—Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+1214/2/202417/6/2026
Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.4)0.32%—Levantoan Woocommerce Vietnam Checkout8/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocommerce Vietnam Checkout allows Stored XSS.This issue affects Woocommerce Vietnam Checkout: from n/a through 2.0.7.
ModificadaAlta (8.8)0.21%—Wpspellcheck31/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.
ModificadaMedia (5.5)0.21%—Maff Electronic Delivery Check System24/1/202417/6/2026
Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on…
ModificadaMedia (5.5)0.23%—Cals-ed Electronic Delivery Check SystemCals-ed Electronic Delivery Item Inspection Support System24/1/202417/6/2026
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity…
ModificadaMedia (5.3)0.60%—Owasp Dependency-check19/1/202414/7/2026
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
ModificadaAlta (7.8)0.18%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
ModificadaAlta (7.8)0.28%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
ModificadaMedia (6.5)0.51%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
ModificadaAlta (7.5)0.52%—Noorsplugin WP Stripe Checkout5/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.
ModificadaCrítica (9.8)0.57%—Mestresdowp Checkout Mestres WP31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6.
ModificadaMedia (6.1)0.48%—W3 Spell Checker23/12/202317/6/2026
A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The…
ModificadaAlta (7.8)0.54%—Checkmk13/12/202317/6/2026
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
Orbitaley — Vulnerabilidades