Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1086 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)1.4%💥 ExploitAnirbandutta9 News-buzzCode-projects Content Management System4/11/202417/6/2026
A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit…
AplazadaMedia (6.5)0.40%—Automattic Newspack Content ConverterAI1/11/202417/6/2026
Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5.
ModificadaAlta (8.8)0.24%—Wp-buy WP Content Copy Protection & NO Right Click20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Content Copy Protection & No Right Click wp-content-copy-protector allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click: from n/a through <= 3.5.9.
ModificadaAlta (8.8)0.21%—Dublue Table OF Contents Plus20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Table of Contents Plus table-of-contents-plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through <= 2408.
ModificadaMedia (4.8)0.37%—Arelthiaphillips ADD Widget After Content18/10/202417/6/2026
The Add Widget After Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AplazadaMedia (6.4)0.27%—Cmsmasters Content ComposerAI9/10/202417/6/2026
The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaAlta (7.1)0.32%—Ays-pro Secure Copy Content Protection AND Content LockingAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection-subscribe-to-view allows Stored XSS.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <=…
AnalizadaMedia (6.1)0.39%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions2/10/202417/6/2026
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes it possible for…
AnalizadaMedia (6.5)0.44%—Madrasthemes MAS Static Content25/9/202417/6/2026
The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract potentially sensitive information from private static…
AnalizadaMedia (5.9)0.28%—Netcat Content Management System19/9/202417/6/2026
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
AnalizadaMedia (5.9)0.28%—Netcat Content Management System19/9/202417/6/2026
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
AnalizadaMedia (6.9)0.43%—Netcat Content Management System19/9/202417/6/2026
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/…
ModificadaMedia (5.4)0.28%—Vanderwijk Content Blocks17/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) custom-post-widget allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): from n/a through <= 3.3.5.
AnalizadaMedia (4.8)0.37%—Ays-pro Secure Copy Content Protection AND Content Locking4/9/202417/6/2026
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AnalizadaMedia (4.8)0.40%—Ays-pro Secure Copy Content Protection AND Content Locking4/9/202417/6/2026
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AplazadaMedia (6.5)0.26%—Wpsc-plugin Structured ContentAI18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.
AnalizadaMedia (6.3)0.21%—SAP Netweaver AbapSAP Netweaver JavaSAP Content ServerSAP WEB Dispatcher13/8/202417/6/2026
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform some unintended actions. This could lead to a low impact on confidentiality and a high impact on the…
AnalizadaMedia (6.1)0.41%—Magazine3 Easy Table OF Contents6/8/202417/6/2026
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
AnalizadaMedia (6.4)0.26%—Doublesharp Remote Content Shortcode1/8/202417/6/2026
The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating…
ModificadaMedia (6.4)0.25%—Json-content-importer Json Content Importer22/7/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.
AplazadaAlta (7.1)0.35%—Obtaininfotech Multisite Content Copier UpdaterAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.This issue affects Multisite Content Copier/Updater: from n/a through 1.5.0.
ModificadaMedia (6.1)0.40%—Hyland Alfresco Content Services20/7/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter htmlid.
ModificadaAlta (8.8)0.68%—Elearningfreak Insert OR Embed Articulate Content15/7/202417/6/2026
The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
AnalizadaAlta (8.8)0.31%—Adamsolymosi Contentlock12/7/202417/6/2026
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack
ModificadaAlta (8.8)0.31%—Adamsolymosi Contentlock12/7/202417/6/2026
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Orbitaley — Vulnerabilidades