Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Areteit Activity Reactions FOR BuddypressAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Activity Reactions For Buddypress activity-reactions-for-buddypress allows Reflected XSS.This issue affects Activity Reactions For Buddypress: from n/a through <= 1.0.22. | |
| Aplazada | Media (6.5) | 0.36% | — | Dev4press CoreactivityAI | 8/4/2025 | 17/6/2026 | The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in all versions up to, and including, 2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Alta (7.1) | 0.29% | — | Erwinwolff Wordpress Activity-o-meter | 7/3/2025 | 17/6/2026 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Analizada | Media (6.3) | 0.47% | — | Melapress WP Activity LOG | 27/2/2025 | 17/6/2026 | WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php. | |
| Analizada | Media (6.1) | 1.4% | — | Melapress WP Activity LOG | 17/2/2025 | 17/6/2026 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (4) | 0.42% | — | Activitypub FederationAIJoin-lemmy LemmyAI | 10/2/2025 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of… | |
| Aplazada | Media (4.3) | 0.17% | — | Winterlock Activity LOGAI | 4/2/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted. | |
| Analizada | Media (5.4) | 0.24% | — | Buddydev Activity Plus Reloaded FOR Buddypress | 24/1/2025 | 17/6/2026 | The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.1 via the 'ajax_preview_link' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to… | |
| Aplazada | Media (5.5) | 0.17% | — | AAT Another Activity TrackerAI | 6/1/2025 | 17/6/2026 | AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to data exfiltration from malicious apps installed on the same device. | |
| Analizada | Alta (7.2) | 0.79% | — | Pojo Activity LOG | 21/11/2024 | 17/6/2026 | The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.5) | 0.40% | — | Yr-activity-linkAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 野人 活动链接推广插件 yr-activity-link allows DOM-Based XSS.This issue affects 活动链接推广插件: from n/a through <= 1.2.0. | |
| Analizada | Media (6.1) | 1.4% | — | Melapress WP Activity LOG | 15/11/2024 | 17/6/2026 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (6.3) | 0.35% | — | Solwin User Activity LOG PROAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in solwin User Activity Log Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Activity Log Pro: from n/a through 2.3.4. | |
| Analizada | Media (5.4) | 0.26% | — | Automattic GhacitivityAutomattic Ghactivity | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha. | |
| Aplazada | Media (6.5) | 0.35% | — | Automattic ActivitypubAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5. | |
| Analizada | Media (5.3) | 0.48% | — | Dev4press Coreactivity | 17/4/2024 | 17/6/2026 | The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value | |
| Aplazada | Alta (8.5) | 0.52% | — | Solwin User Activity LOG PROAI | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin User Activity Log Pro.This issue affects User Activity Log Pro: from n/a through 2.3.4. | |
| Aplazada | Alta (7.6) | 0.52% | — | Solwininfotech User Activity LOGAI | 10/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n/a through 1.8. | |
| Modificada | Alta (8.8) | 0.88% | — | Melapress WP Activity LOG | 9/4/2024 | 17/6/2026 | The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.33% | — | Melapress WP Activity LOG | 29/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows Stored XSS.This issue affects WP Activity Log: from n/a through 4.6.1. | |
| Modificada | Alta (8.8) | 0.30% | — | Wbcomdesigns Buddypress Activity Social Share | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions. | |
| Modificada | Crítica (9.8) | 0.68% | — | Solwininfotech User Activity LOG | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This issue affects User Activity Log: from n/a through 1.6.2. | |
| Modificada | Media (5.4) | 0.46% | — | Solwininfotech User Activity LOG | 16/10/2023 | 17/6/2026 | The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 0.66% | — | Solwininfotech User Activity LOG | 16/10/2023 | 17/6/2026 | This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic. | |
| Modificada | Media (5.4) | 0.48% | — | Automattic Activitypub | 16/10/2023 | 17/6/2026 | The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks |