Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.7)0.54%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
AnalizadaCrítica (9.9)0.72%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
AnalizadaAlta (7.7)0.46%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.
AnalizadaAlta (8.6)0.32%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
AnalizadaAlta (8.6)0.49%—RBI Restaurant Brands International Assistant17/10/202517/6/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.
AnalizadaMedia (5.8)0.39%—RBI Restaurant Brands International Assistant17/10/202530/9/2026
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.
AplazadaAlta (8.5)0.26%—Quadlayers Perfect Brands FOR WoocommerceAI22/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocommerce-brands allows SQL Injection.This issue affects Perfect Brands for WooCommerce: from n/a through <= 3.6.2.
AplazadaMedia (5.4)0.27%—Brandexponents Oshine CoreAI22/9/202517/6/2026
Missing Authorization vulnerability in brandexponents Oshine Core oshine-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oshine Core: from n/a through <= 1.5.5.
AplazadaMedia (6.4)0.27%—BrandfolderAI16/7/202517/6/2026
The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 5.0.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaMedia (4)0.20%—Dracoon Branding ServiceAI15/7/202517/6/2026
DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users could inject HTML code…
AplazadaMedia (4.3)0.15%—Imw3 MY WP BrandAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in imw3 My Wp Brand my-wp-brand allows Cross Site Request Forgery.This issue affects My Wp Brand: from n/a through <= 1.1.3.
AplazadaAlta (7.1)0.39%—Rebrandpress Rebrand Fluent FormsAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rebrandpress Rebrand Fluent Forms rebrand-fluent-forms allows Reflected XSS.This issue affects Rebrand Fluent Forms: from n/a through <= 1.0.
AplazadaAlta (7.1)0.26%—Brandexponents Oshine ModulesAI16/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Oshine Modules oshine-modules allows Reflected XSS.This issue affects Oshine Modules: from n/a through < 3.3.8.
AnalizadaMedia (5.4)0.38%—Gsplugins Woocommerce Brands12/2/202517/6/2026
The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_brand' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user…
AplazadaMedia (5.4)0.26%—Brandexponents Oshine ModulesAI31/1/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshine Modules: from n/a through < 3.3.8.
AnalizadaMedia (4.6)0.31%—Themesbrand Chatvia16/1/202517/6/2026
Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via the User profile name and image upload functions.
AnalizadaMedia (4.6)0.45%—Themesbrand Chatvia16/1/202517/6/2026
An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function.
AplazadaMedia (5.3)0.32%—Imw3 MY WP BrandAI31/12/202417/6/2026
Missing Authorization vulnerability in imw3 My Wp Brand my-wp-brand.This issue affects My Wp Brand: from n/a through <= 1.1.2.
AplazadaMedia (6.5)0.23%—Yaycommerce BrandAI16/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand brand allows Stored XSS.This issue affects Brand: from n/a through <= 1.1.6.
AplazadaAlta (7.1)0.21%—Brandt-net Display Future PostsAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in brandt-net Display Future Posts display-future-posts allows Stored XSS.This issue affects Display Future Posts: from n/a through <= 0.2.3.
AplazadaMedia (5.3)0.50%—Berocket Brands FOR WoocommerceAI13/12/202417/6/2026
Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2.
AplazadaMedia (4.3)1.1%💥 PoCLiquidpoll Advanced Polls FOR Creators AND BrandsAI13/12/202417/6/2026
Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.
AplazadaAlta (8.8)0.51%—DebrandingAI12/12/202417/6/2026
The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaMedia (5.3)0.43%—Acato Branded Social ImagesAI9/12/202417/6/2026
Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0.
AplazadaMedia (6.1)0.55%—Wpmudev BrandaAI21/11/202417/6/2026
The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated attackers to inject…
Orbitaley — Vulnerabilidades