Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

751 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.50%—Checkmk26/6/202317/6/2026
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
ModificadaMedia (4.8)0.37%—Piwebsolution Add-to-cart-direct-checkout-for-woocommerce26/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin <= 2.1.48 versions.
ModificadaAlta (8.1)0.78%—Jenkins Checkmarx14/6/202317/6/2026
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
ModificadaMedia (6.1)1.3%💥 ExploitWpdesk Flexible Checkout Fields7/6/202317/6/2026
The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via…
ModificadaMedia (6.1)0.55%—Managewp Broken Link Checker5/6/202317/6/2026
Se ha encontrado una vulnerabilidad en el plugin Broken Link Checker hasta la versión 1.10.1 en WordPress. Se ha declarado como problemática. Esta vulnerabilidad afecta a la función "options_page" del archivo "core/core.php" del componente "Settings Page". La manipulación del argumento…
ModificadaAlta (8.8)0.27%—Wordpress Health Check & Troubleshooting25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.
ModificadaMedia (4.3)0.59%—CheckmkTribe29 Checkmk17/5/202317/6/2026
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
ModificadaAlta (8.8)0.97%—CheckmkTribe29 Checkmk17/5/202317/6/2026
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
ModificadaAlta (7.5)0.54%—Tribe29 Checkmk Appliance Firmware15/5/202317/6/2026
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
ModificadaMedia (6.1)0.38%—Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop9/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions.
ModificadaMedia (5.5)0.22%—Checkmk2/5/202317/6/2026
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
ModificadaMedia (6.1)0.85%💥 ExploitPlainviewplugins Mycryptocheckout2/5/202317/6/2026
The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.41%—Tribe29 Checkmk Appliance Firmware20/4/202317/6/2026
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
ModificadaAlta (8.8)0.39%—Checkmk20/4/202317/6/2026
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges…
ModificadaMedia (5.5)0.22%—Tribe29 Checkmk Appliance Firmware18/4/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
ModificadaAlta (8.8)0.68%—Tribe29 Checkmk18/4/202317/6/2026
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
ModificadaMedia (4.3)0.40%—Checkmk18/4/202317/6/2026
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
ModificadaMedia (6.1)0.56%—Wpmudev Broken Link Checker8/4/202317/6/2026
A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Affected by this issue is the function print_module_list/show_warnings_section_notice/status_text/ui_get_action_links. The manipulation leads to cross site scripting. The attack may be launched…
ModificadaMedia (5.3)0.91%—CheckmkTribe29 Checkmk4/4/202317/6/2026
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.
ModificadaMedia (5.4)0.46%—Jenkins Cppcheck2/4/202317/6/2026
Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.
ModificadaMedia (6.1)0.41%—Levantoan Woocommerce Vietnam Checkout27/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions.
ModificadaMedia (5.4)0.40%—CheckmkTribe29 Checkmk20/3/202317/6/2026
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
ModificadaMedia (4.8)0.37%—Plustime Service Area Postcode Checker20/3/202317/6/2026
Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions.
ModificadaMedia (4.8)0.35%—Tipsandtricks-hq WP Express Checkout17/3/202317/6/2026
The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject…
ModificadaCrítica (9.8)4.4%💥 ExploitNajeebmedia Woocommerce Checkout Field Manager6/3/202317/6/2026
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server