Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Amentotech DoctreatAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmentoTech Doctreat doctreat allows Reflected XSS.This issue affects Doctreat: from n/a through <= 1.6.7.
AplazadaMedia (6.3)0.27%—Amenotech DoctreatAI22/10/202517/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.
AplazadaAlta (7.7)0.43%—Amenotech TaskbotAI22/10/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Taskbot taskbot allows Path Traversal.This issue affects Taskbot: from n/a through <= 6.4.
AplazadaAlta (8.2)0.31%—Amenotech Private Limited WpguppyAIAmenotech Private Limited Wpguppy LiteAI22/10/202517/6/2026
Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPGuppy: from n/a through <= 1.1.4.
AplazadaMedia (6.4)0.24%—WP Tournament RegistrationAI6/8/202517/6/2026
The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AnalizadaMedia (5.4)0.19%—Blakelong Tournament Bracket Generator26/6/202517/6/2026
The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AnalizadaAlta (8.8)0.60%—Amentotech Workreap12/6/202517/6/2026
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'workreap_temp_upload_to_media' function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers,…
AnalizadaCrítica (9.8)0.48%—Amentotech Workreap12/6/202517/6/2026
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account with an email…
AplazadaAlta (8.5)0.39%—Amentotech WP GuppyAI9/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy wp-guppy allows SQL Injection.This issue affects WP Guppy: from n/a through <= 4.3.3.
AplazadaMedia (6.5)0.26%—Jetmonsters Getwid-megamenuAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block getwid-megamenu allows Stored XSS.This issue affects Mega Menu Block: from n/a through <= 1.0.6.
AnalizadaMedia (6.5)1.6%💥 ExploitLukashuser EKC Tournament Manager15/5/202517/6/2026
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory
AnalizadaMedia (5.4)0.18%—Lukashuser EKC Tournament Manager15/5/202517/6/2026
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (5.4)0.18%—Lukashuser EKC Tournament Manager15/5/202517/6/2026
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AplazadaAlta (7.1)0.24%—Jajapagamentos Ja-ja Pagamentos FOR WoocommerceAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-Já Pagamentos for WooCommerce wc-ja-ja-pagamentos-multicaixa-express allows Reflected XSS.This issue affects Já-Já Pagamentos for WooCommerce: from n/a through <= 1.3.0.
AplazadaAlta (8.5)0.49%—Amentotech Private Limited Wpguppy LiteAI27/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows SQL Injection.This issue affects WPGuppy: from n/a through <= 1.1.3.
AnalizadaCrítica (9.8)0.43%—Amentotech Workreap12/3/202517/6/2026
The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly validating a user's identity prior to (1) performing a social auto-login or (2) updating their profile details (e.g. password). This makes it…
AplazadaMedia (5.3)0.78%—Siam Industria DE Automacao E MonitoramentoAI16/2/202517/6/2026
A vulnerability, which was classified as problematic, has been found in SIAM Industria de Automação e Monitoramento SIAM 2.0. This issue affects some unknown processing of the file /qrcode.jsp. The manipulation of the argument url leads to cross site scripting. The attack may be initiated remotely. The exploit has…
AplazadaMedia (6.5)0.40%—Amentotech WpguppyAI3/2/202517/6/2026
Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaMedia (6.5)0.32%—Xiamen Meitu Technology BeautycamAI27/1/202517/6/2026
An issue in Xiamen Meitu Technology Co., Ltd. BeautyCam iOS v12.3.60 allows attackers to access sensitive user information via supplying a crafted link.
AnalizadaMedia (6.6)0.37%—Boozallen Megamenu Framework9/1/202517/6/2026
Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*.
AplazadaAlta (8.8)0.41%—Amentotech Private Limited WpguppyAIAmentotech Private Limited Wpguppy LiteAI7/1/202517/6/2026
Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalation.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaCrítica (9.8)0.51%—Amenotech Private Limited WpguppyAI7/1/202517/6/2026
Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injection.This issue affects WPGuppy: from n/a through <= 1.1.0.
AplazadaMedia (6.5)0.35%—Auburnforest DatamentorAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AuburnForest DataMentor datamentor allows DOM-Based XSS.This issue affects DataMentor: from n/a through <= 1.7.
AplazadaBaja (2.3)0.56%—Filamentphp FilamentAI7/11/202417/6/2026
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driver to something production-ready like `s3` when deploying their app, without…
AplazadaCrítica (9.6)0.23%—Lukashuser EKC Tournament ManagerAI31/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through <= 2.2.1.
Orbitaley — Vulnerabilidades