Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.32% | — | Quiz Maker BusinessAIQuiz Maker DeveloperAIQuiz Maker AgencyAI | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient input… | |
| Aplazada | Alta (7.3) | 0.55% | — | Quiz Maker BusinessAIQuiz Maker DeveloperAIQuiz Maker AgencyAI | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users to execute an… | |
| Aplazada | Alta (7.2) | 0.47% | — | Ays-pro Quiz Maker BusinessAIAys-pro Quiz Maker DeveloperAIAys-pro Quiz Maker AgencyAI | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and… | |
| Modificada | Alta (8.8) | 0.21% | — | Rarathemes Travel Agency | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through <= 1.4.9. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Inspry Agency ToolkitAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Privilege Escalation.This issue affects Agency Toolkit: from n/a through <= 1.0.23. | |
| Aplazada | Media (6.5) | 0.24% | — | Agency Dominion INC FusionAI | 19/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion.This issue affects Fusion: from n/a through <= 1.6.1. | |
| Aplazada | Crítica (10) | 0.66% | — | HK Digital Agency LLC TAX Service Electronic HDMAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM virtual-hdm-for-taxservice-am allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.8) | 0.50% | — | Deco.agency DE BrandingAI | 20/11/2024 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Bigfiveagency CF7 Reply ManagerAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in bigfiveagency CF7 Reply Manager cf7-reply-manager.This issue affects CF7 Reply Manager: from n/a through <= 1.2.3. | |
| Analizada | Crítica (9.8) | 0.48% | — | Cozythemes Hello Agency | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in CozyThemes Hello Agency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hello Agency: from n/a through 1.0.5. | |
| Analizada | Alta (8.1) | 0.57% | — | Mayurik GAS Agency Management System | 3/6/2024 | 17/6/2026 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php. | |
| Analizada | Crítica (9.8) | 0.51% | — | Mayurik GAS Agency Management System | 3/6/2024 | 17/6/2026 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=. | |
| Analizada | Media (5.3) | 0.65% | — | Mayurik GAS Agency Management System | 17/5/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (7.2) | 0.60% | — | Mooveagency Import XML AND RSS FeedsAI | 7/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5. | |
| Modificada | Media (6.1) | 0.53% | — | Dstar2018 Agency | 7/11/2023 | 17/6/2026 | A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument QSType/QuickSearch leads to cross site scripting. The attack can be launched remotely. The patch is named… | |
| Modificada | Crítica (9.8) | 41% | 💥 Exploit | Mooveagency Import XML AND RSS Feeds | 25/9/2023 | 17/6/2026 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42)… | |
| Modificada | Alta (7.2) | 2.0% | 💥 PoC | Mooveagency Import XML AND RSS Feeds | 25/9/2023 | 17/6/2026 | The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution. | |
| Modificada | Media (4.3) | 0.25% | — | Mooveagency User Activity Tracking AND LOG | 30/8/2023 | 17/6/2026 | The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks | |
| Modificada | Media (6.5) | 0.32% | — | Mooveagency Gdpr Cookie Compliance | 30/8/2023 | 17/6/2026 | The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks | |
| Modificada | Alta (7.2) | 1.5% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php. | |
| Modificada | Media (4.8) | 0.64% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php. | |
| Modificada | Alta (7.2) | 1.5% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php. |