Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
430 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.6% | — | Getshortcodes Shortcodes Ultimate | 7/7/2017 | 17/6/2026 | Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 3.4% | — | Designsandcode Forget About Shortcode Buttons | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1 | |
| Modificada | Media (4.3) | 4.2% | — | Login Widget With Shortcode Project Login Widget With Shortcode | 15/10/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the custom_style_afo parameter on the… | |
| Modificada | Media (5) | 14% | — | Werdswords Download Shortcode | 3/9/2014 | 17/6/2026 | Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Baja (2.1) | 1.6% | — | Cartpauj Shortcode-redirect | 8/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (1) url or (2) sec attributes in a redirect tag. |