Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.43% | — | Imsoftware WP Imap AuthAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imsoftware WP IMAP Auth wp-imap-authentication allows Reflected XSS.This issue affects WP IMAP Auth: from n/a through <= 4.0.1. | |
| Modificada | Media (6.1) | 0.45% | — | Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+10 | 22/1/2025 | 17/6/2026 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | |
| Aplazada | Alta (7.1) | 0.26% | — | Iova.mihai Social PUG Author BOXAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai Social Pug: Author Box allows Reflected XSS. This issue affects Social Pug: Author Box: from n/a through 1.0.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Shiv Prakash Tiwari WP Service Payment Form With AuthorizenetAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari WP Service Payment Form With Authorize.net wp-service-payment-form-with-authorizenet allows Reflected XSS.This issue affects WP Service Payment Form With Authorize.net: from n/a through <= 2.6.0. | |
| Aplazada | Alta (7.1) | 0.16% | — | Nazmul Ahsan Rename Author SlugAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan Rename Author Slug rename-author-slug allows Stored XSS.This issue affects Rename Author Slug: from n/a through <= 1.2.0. | |
| Aplazada | Alta (7.1) | 0.32% | — | Yamna Khawaja KNR Author List WidgetAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja KNR Author List Widget knr-author-list-widget allows Reflected XSS.This issue affects KNR Author List Widget: from n/a through <= 3.1.1. | |
| Analizada | Media (6.1) | 0.25% | — | Miniorange Oauth & Openid Connect Single Sign-on | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0,… | |
| Analizada | Alta (7.3) | 0.32% | — | Basic Http Authentication Project Basic Http Authentication | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4. | |
| Analizada | Crítica (9.8) | 0.46% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0. | |
| Analizada | Crítica (9.8) | 0.64% | — | Rest & Json API Authentication Project Rest & Json API Authentication | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13. | |
| Analizada | Crítica (9.8) | 0.56% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Paul Bearne Author AvatarsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.23. | |
| Aplazada | Alta (7.1) | 0.26% | — | Asokaaso2 Kikx Simple Post Author FilterAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in asokaaso2 Kikx Simple Post Author Filter sa-post-author-filter allows Reflected XSS.This issue affects Kikx Simple Post Author Filter: from n/a through <= 1.0. | |
| Aplazada | Media (6.3) | 0.46% | — | Guzzle Oauth SubscriberAI | 6/1/2025 | 17/6/2026 | Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This vulnerability is fixed in 0.8.1. | |
| Aplazada | Media (5.3) | 0.61% | — | NET OauthAI | 3/1/2025 | 17/6/2026 | In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong. | |
| Modificada | Alta (7.2) | 0.48% | — | Afthemes WP Post Author | 2/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows SQL Injection.This issue affects WP Post Author: from n/a through <= 3.8.2. | |
| Analizada | Alta (7.9) | 0.39% | — | Better-auth Better Auth | 30/12/2024 | 17/6/2026 | Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to malicious websites. This issue affects users relying on email verification links… | |
| Aplazada | Media (5.3) | 0.39% | — | Accept Authorize NET Payments Using Contact Form 7AI | 18/12/2024 | 17/6/2026 | The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes it possible for unauthenticated attackers to extract configuration data which can be used to aid in other attacks. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Appgenix Infotech Firebase OTP AuthenticationAI | 13/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication authentication-via-otp-using-firebase allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.1) | 0.43% | — | WP Service Payment Form With Authorize NETAI | 12/12/2024 | 17/6/2026 | The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (8.1) | 0.79% | — | Oauth SSOAI | 12/12/2024 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any… | |
| Aplazada | Alta (7.3) | 0.58% | — | Wpkube Authors ListAI | 4/12/2024 | 17/6/2026 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Aplazada | Crítica (9.8) | 1.6% | 💥 Exploit | Adapt Learning Adapt Authoring ToolAI | 25/11/2024 | 17/6/2026 | A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. The vulnerability occurs due to insufficient validation of user input, which is used as a query in Mongoose's find()… | |
| Aplazada | Media (4.3) | 0.33% | — | Adapt Learning Adapt Authoring ToolAI | 25/11/2024 | 17/6/2026 | Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended… | |
| Analizada | Media (6.3) | 0.55% | — | Goauthentik Authentik | 21/11/2024 | 17/6/2026 | authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the SECRET_KEY, which is used to authenticate the endpoint. The /-/metrics/ endpoint returns Prometheus metrics and is not intended to be accessed directly, as… |