Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Emarketdesign Wp-ticketAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Stored XSS.This issue affects WP Ticket Customer Service Software & Support Ticket System: from n/a through <= 6.0.2. | |
| Aplazada | Media (4.3) | 0.17% | — | Miniorange Oauth Single Sign ONAI | 26/9/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.26.12. This is due to using a predictable state parameter (base64 encoded app name) without any randomness in the OAuth flow. This makes it possible for unauthenticated… | |
| Analizada | Media (6.5) | 0.34% | — | Magdesign Pocketvj Control Panel Firmware | 23/9/2025 | 17/6/2026 | An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component. | |
| Aplazada | Media (6.5) | 0.17% | — | Emarketdesign Request A QuoteAI | 23/9/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Request a Quote request-a-quote allows Stored XSS.This issue affects Request a Quote: from n/a through <= 2.5.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign SoledadAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: from n/a through <= 8.6.8. | |
| Aplazada | Alta (7.5) | 0.41% | — | Pencidesign SoledadAI | 22/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects Soledad: from n/a through <= 8.6.8. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci Shortcodes AND PerformanceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through < 6.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci PortfolioAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Portfolio penci-portfolio allows DOM-Based XSS.This issue affects Penci Portfolio: from n/a through <= 3.5. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci RecipeAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Recipe penci-recipe allows DOM-Based XSS.This issue affects Penci Recipe: from n/a through <= 4.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci PodcastAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Podcast penci-podcast allows DOM-Based XSS.This issue affects Penci Podcast: from n/a through <= 1.6. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci Filter EverythingAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Filter Everything penci-filter-everything allows DOM-Based XSS.This issue affects Penci Filter Everything: from n/a through < 1.7. | |
| Aplazada | Media (6.5) | 0.20% | — | AUM Watcharapon Designil Pdpa ThailandAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aum Watcharapon Designil PDPA Thailand pdpa-thailand allows Stored XSS.This issue affects Designil PDPA Thailand: from n/a through <= 2.0.1. | |
| Aplazada | Media (5.4) | 0.28% | — | Solwininfotech Blog DesignerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in solwininfotech Blog Designer blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blog Designer: from n/a through <= 3.1.8. | |
| Aplazada | Media (4.3) | 0.44% | — | Codexpert CodesignerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Codexpert, Inc CoDesigner woolementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoDesigner: from n/a through <= 4.29. | |
| Aplazada | Media (4.3) | 0.29% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.8. | |
| Analizada | Crítica (9.8) | 0.55% | — | Blackmagicdesign Atem Mini PRO Firmware | 22/9/2025 | 17/6/2026 | The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol preamble that leaks the video mode, routing configuration, input/output labels, device model, and even internal… | |
| Analizada | Crítica (9.8) | 0.53% | — | Blackmagicdesign WEB Presenter HD Firmware | 22/9/2025 | 17/6/2026 | The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream… | |
| Aplazada | Media (6.5) | 0.28% | — | Gcsdesign WP Category DropdownAI | 22/9/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandrika Sista WP Category Dropdown wp-category-dropdown allows Stored XSS.This issue affects WP Category Dropdown: from n/a through <= 1.9. | |
| Analizada | Crítica (9.8) | 0.64% | — | Blackmagicdesign WEB Presenter HD FirmwareBlackmagicdesign WEB Presenter 4K Firmware | 22/9/2025 | 17/6/2026 | Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality. No credentials or authentication mechanisms are required to… | |
| Aplazada | Media (4.3) | 0.13% | — | Custom Login AND Signup WidgetAI | 20/9/2025 | 17/6/2026 | The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in the /frndzk_adminclsw.php file. This makes it possible for unauthenticated attackers to change the email and username… | |
| Aplazada | Alta (7.1) | 0.25% | — | Vizly WEB Design Real Estate PackagesAI | 19/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web Design Real Estate Packages allows Content Spoofing, CAPEC - 593 - Session Hijacking, CAPEC - 591 - Reflected XSS. This issue affects Real Estate Packages: before 5.1. | |
| Aplazada | Alta (7.1) | 0.20% | — | Dokuzsoft Technology E-commerce WEB Design ProductAI | 17/9/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology E-Commerce Web Design Product allows XSS Through HTTP Headers. This issue affects E-Commerce Web Design Product: before 11.08.2025. | |
| Modificada | Alta (7.5) | 0.33% | — | Signify WIZ Connected | 16/9/2025 | 5/7/2026 | An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address. | |
| Aplazada | Media (4.3) | 0.13% | — | Blog Designer FOR ElementorAI | 11/9/2025 | 17/6/2026 | The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.7. This is due to missing or incorrect nonce validation on the bdfe_install_activate_rswpbs_only function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.17% | — | LH SigningAI | 11/9/2025 | 30/9/2026 | The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.83. This is due to missing or incorrect nonce validation on the plugin_options function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted… |