Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.66% | — | Suiteplugins Video AND Photo Gallery FOR Ultimate MemberAI | 16/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.35% | — | Silverplugins217 Check Pincode FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Check Pincode For Woocommerce check-pincode-for-woocommerce allows Reflected XSS.This issue affects Check Pincode For Woocommerce: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Pickplugins Mail PickerAI | 13/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker mail-picker allows Object Injection.This issue affects Mail Picker: from n/a through <= 1.0.14. | |
| Aplazada | Media (4.3) | 0.69% | — | Team Plugins360 Automatic Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3. | |
| Modificada | Crítica (9.8) | 0.93% | — | Coolplugins Cryptocurrency Widgets | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.2. | |
| Aplazada | Media (5.4) | 0.45% | — | Gsplugins GS Pins FOR PinterestAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Pins for Pinterest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Pins for Pinterest: from n/a through 1.6.7. | |
| Analizada | Alta (7.7) | 0.76% | — | Fooplugins Foogallery | 10/12/2024 | 17/6/2026 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which can contain… | |
| Aplazada | Media (4.7) | 0.41% | — | Aviplugins Login Widget With ShortcodeAI | 9/12/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode login-sidebar-widget allows Phishing.This issue affects Login Widget With Shortcode: from n/a through <= 6.1.2. | |
| Aplazada | Alta (7.5) | 0.76% | — | Fullworksplugins Quick Paypal PaymentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25. | |
| Aplazada | Media (5.3) | 0.57% | — | Fantasticplugins Fantastic Content Protector FreeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fantastic Plugins Fantastic Content Protector Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fantastic Content Protector Free: from n/a through 2.6. | |
| Aplazada | Media (6.5) | 0.71% | — | Fullworksplugins Quick Contact FormAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Contact Form : from n/a through 8.0.3.1. | |
| Aplazada | Media (5.3) | 0.66% | — | Fullworksplugins Quick Event ManagerAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4. | |
| Aplazada | Media (5.3) | 0.36% | — | Pickplugins Related PostsAI | 5/12/2024 | 17/6/2026 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for… | |
| Analizada | Media (5.4) | 0.29% | — | Gsplugins GS Pinterest Portfolio | 3/12/2024 | 17/6/2026 | The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.5) | 0.29% | — | Pickplugins Mail-pickerAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Mail Picker mail-picker allows DOM-Based XSS.This issue affects Mail Picker: from n/a through <= 1.0.15. | |
| Modificada | Crítica (9.8) | 0.66% | — | Coolplugins Cryptocurrency Widgets FOR Elementor | 30/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through <=… | |
| Aplazada | Alta (7.5) | 0.73% | — | Absoluteplugins Absolute Addons FOR ElementorAI | 28/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-addons allows Local Code Inclusion.This issue affects Absolute Addons For Elementor: from n/a through <= 1.0.14. | |
| Aplazada | Media (4.3) | 0.45% | — | Bplugins Easy Twitter FeedAI | 22/11/2024 | 17/6/2026 | The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.6 via the [etf] shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected,… | |
| Analizada | Media (6.5) | 0.51% | — | Bplugins Button Block | 21/11/2024 | 17/6/2026 | The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.21% | — | Woopy Plugins Smartlink Dynamic UrlsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs smartlink-dinamic-urls allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through <= 1.1.0. | |
| Analizada | Media (6.1) | 0.35% | — | Wpplugins Hide MY WP Ghost | 15/11/2024 | 17/6/2026 | The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Really-simple-plugins Really Simple Security | 15/11/2024 | 17/6/2026 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for… | |
| Modificada | Media (5.4) | 0.27% | — | Coolplugins WEB Stories Widgets FOR Elementor | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cool Plugins Web Stories Widgets For Elementor shortcodes-for-amp-web-stories-and-elementor-widget allows Stored XSS.This issue affects Web Stories Widgets For Elementor: from n/a through <= 1.1. | |
| Modificada | Media (5.4) | 0.24% | — | Pluginspoint Kento ADS Rotator | 10/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Kento Ads Rotator kento-ads-rotator allows Stored XSS.This issue affects Kento Ads Rotator: from n/a through <= 1.3. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Leopardplugins Leopard Offload MediaAI | 9/11/2024 | 17/6/2026 | The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the import_settings() function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with… |