Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.54% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers. | |
| Analizada | Crítica (9.9) | 0.72% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation. | |
| Analizada | Alta (7.7) | 0.46% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users. | |
| Analizada | Alta (8.6) | 0.32% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages. | |
| Analizada | Alta (8.6) | 0.49% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 17/6/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account. | |
| Analizada | Media (5.8) | 0.39% | — | RBI Restaurant Brands International Assistant | 17/10/2025 | 30/9/2026 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume. | |
| Aplazada | Alta (8.5) | 0.26% | — | Quadlayers Perfect Brands FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocommerce-brands allows SQL Injection.This issue affects Perfect Brands for WooCommerce: from n/a through <= 3.6.2. | |
| Aplazada | Media (5.4) | 0.27% | — | Brandexponents Oshine CoreAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in brandexponents Oshine Core oshine-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oshine Core: from n/a through <= 1.5.5. | |
| Aplazada | Media (6.4) | 0.27% | — | BrandfolderAI | 16/7/2025 | 17/6/2026 | The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 5.0.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (4) | 0.20% | — | Dracoon Branding ServiceAI | 15/7/2025 | 17/6/2026 | DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users could inject HTML code… | |
| Aplazada | Media (4.3) | 0.15% | — | Imw3 MY WP BrandAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in imw3 My Wp Brand my-wp-brand allows Cross Site Request Forgery.This issue affects My Wp Brand: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.1) | 0.39% | — | Rebrandpress Rebrand Fluent FormsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rebrandpress Rebrand Fluent Forms rebrand-fluent-forms allows Reflected XSS.This issue affects Rebrand Fluent Forms: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Brandexponents Oshine ModulesAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Oshine Modules oshine-modules allows Reflected XSS.This issue affects Oshine Modules: from n/a through < 3.3.8. | |
| Analizada | Media (5.4) | 0.38% | — | Gsplugins Woocommerce Brands | 12/2/2025 | 17/6/2026 | The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_brand' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Media (5.4) | 0.26% | — | Brandexponents Oshine ModulesAI | 31/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8. | |
| Analizada | Media (4.6) | 0.31% | — | Themesbrand Chatvia | 16/1/2025 | 17/6/2026 | Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via the User profile name and image upload functions. | |
| Analizada | Media (4.6) | 0.45% | — | Themesbrand Chatvia | 16/1/2025 | 17/6/2026 | An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function. | |
| Aplazada | Media (5.3) | 0.32% | — | Imw3 MY WP BrandAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in imw3 My Wp Brand my-wp-brand.This issue affects My Wp Brand: from n/a through <= 1.1.2. | |
| Aplazada | Media (6.5) | 0.23% | — | Yaycommerce BrandAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand brand allows Stored XSS.This issue affects Brand: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.21% | — | Brandt-net Display Future PostsAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in brandt-net Display Future Posts display-future-posts allows Stored XSS.This issue affects Display Future Posts: from n/a through <= 0.2.3. | |
| Aplazada | Media (5.3) | 0.50% | — | Berocket Brands FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2. | |
| Aplazada | Media (4.3) | 1.1% | 💥 PoC | Liquidpoll Advanced Polls FOR Creators AND BrandsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68. | |
| Aplazada | Alta (8.8) | 0.51% | — | DebrandingAI | 12/12/2024 | 17/6/2026 | The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.43% | — | Acato Branded Social ImagesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0. | |
| Aplazada | Media (6.1) | 0.55% | — | Wpmudev BrandaAI | 21/11/2024 | 17/6/2026 | The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated attackers to inject… |