Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.16% | — | Nghialuu Zalo Official Live ChatAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat zalo-official-live-chat allows Cross Site Request Forgery.This issue affects Zalo Official Live Chat: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Matat Technologies Deliver VIA Shipos FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matat Technologies Deliver via Shipos for WooCommerce wc-shipos-delivery allows Reflected XSS.This issue affects Deliver via Shipos for WooCommerce: from n/a through <= 2.1.7. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Claudio Adrian Marrero ChatliveAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Marrero CHATLIVE chatlive allows SQL Injection.This issue affects CHATLIVE: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | GUY Bedford Live CSSAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpion Live css css-live allows Stored XSS.This issue affects Live css: from n/a through <= 1.3. | |
| Aplazada | Media (5.4) | 0.44% | — | W3eden Live FormsAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Forms: from n/a through <= 4.8.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Eric-oliver Machler Dsgvo YoutubeAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube dsgvo-youtube allows DOM-Based XSS.This issue affects DSGVO Youtube: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Dalziel Windows-live-writerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dalziel Windows Live Writer windows-live-writer allows Stored XSS.This issue affects Windows Live Writer: from n/a through <= 0.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Sodena Frescochat Live ChatAISodena Flexytalk-widgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sodena FrescoChat Live Chat flexytalk-widget allows Stored XSS.This issue affects FrescoChat Live Chat: from n/a through <= 3.2.6. | |
| Aplazada | Media (4.3) | 0.25% | — | W3eden Live FormsAI | 8/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= 4.8.5. | |
| Aplazada | Media (5.9) | 0.41% | — | Socialintents Live-chat-support-by-social-intentsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Social Intents live-chat-support-by-social-intents allows Stored XSS.This issue affects Social Intents: from n/a through <= 1.6.19. | |
| Aplazada | Media (6.3) | 0.58% | — | Arnog MathliveAI | 1/4/2025 | 17/6/2026 | Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function. | |
| Aplazada | Media (5.4) | 0.45% | — | Oliver Boyers PIN GeneratorAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Oliver Boyers Pin Generator pin-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pin Generator: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.4) | 0.25% | — | Livemesh Elementor AddonsAI | 1/4/2025 | 17/6/2026 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.26% | — | Crazycric Ultimate Live Cricket LiteAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crazycric Ultimate Live Cricket WordPress Lite ultimate-live-cricket-lite allows Stored XSS.This issue affects Ultimate Live Cricket WordPress Lite: from n/a through <= 1.4.2. | |
| Aplazada | Media (5.4) | 0.49% | — | W3eden Live FormsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjada Live Forms liveforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Forms: from n/a through <= 4.8.4. | |
| Aplazada | Alta (7.1) | 0.36% | — | Dangngocbinh Zalo Live ChatAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dang Ngoc Binh Zalo Live Chat zalo-live-chat allows Reflected XSS.This issue affects Zalo Live Chat: from n/a through <= 1.1.0. | |
| Aplazada | Alta (8.8) | 0.22% | — | Foodbakery Delivery Restaurant DirectoryAI | 19/3/2025 | 17/6/2026 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save,… | |
| Aplazada | Media (5.9) | 0.54% | — | Powerpack Print Invoice Delivery NotesAI | 8/3/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Aplazada | Crítica (9.3) | 0.62% | — | Livewire VoltAI | 5/3/2025 | 17/6/2026 | Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lead to remote code execution within Volt components. This vulnerability is fixed in 1.7.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Lafka Multi Store Burger Pizza Food DeliveryAI | 5/3/2025 | 17/6/2026 | The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.59% | — | Videowhisper Broadcast Live VideoAI | 25/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Path Traversal.This issue affects Broadcast Live Video: from n/a through <= 6.2. | |
| Aplazada | Alta (8.6) | 0.54% | — | Videowhisper Broadcast Live VideoAI | 25/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Path Traversal.This issue affects Broadcast Live Video: from n/a through <= 6.2. | |
| Analizada | Media (5.4) | 0.29% | — | Oliverfriedmann Ziggeo | 21/2/2025 | 17/6/2026 | The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.9) | 0.63% | — | Bishopfox Sliver | 19/2/2025 | 17/6/2026 | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed… | |
| Aplazada | Media (6.1) | 0.31% | — | Cisco Broadworks Application Delivery PlatformAI | 19/2/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… |