Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.33% | — | Call FOR PriceAI | 2/5/2026 | 17/6/2026 | The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Aplazada | Crítica (10) | 0.57% | — | Js8callAIJs8call-improvedAI | 1/5/2026 | 17/6/2026 | JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp. | |
| Aplazada | Media (4.3) | 0.23% | — | Call TO Action PluginAI | 22/4/2026 | 17/6/2026 | The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_page() function which handles saving, creating, and deleting plugin settings. The form rendered on the settings page does… | |
| Analizada | Alta (8.4) | 0.23% | — | Intouchapp Intouch Contacts & Caller ID | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Modificada | Alta (8.7) | 0.76% | — | OpenclawOpenclaw/voice-call | 11/3/2026 | 17/6/2026 | OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated clients to establish connections. Remote attackers can hold idle pre-authenticated… | |
| Aplazada | Media (5.3) | 0.36% | — | CallbackkillerAI | 14/2/2026 | 17/6/2026 | The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cbk_save() function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to modify the plugin's site ID settings via the… | |
| Aplazada | Media (4.3) | 0.17% | — | MMA Call TrackingAI | 11/2/2026 | 17/6/2026 | The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.15. This is due to missing nonce validation when saving plugin configuration on the `mma_call_tracking_menu` admin page. This makes it possible for unauthenticated attackers to modify call… | |
| Aplazada | Media (5.3) | 0.26% | — | Custom Fonts Host Your Fonts LocallyAI | 20/1/2026 | 17/6/2026 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Alta (8.8) | 0.34% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025. | |
| Aplazada | Media (5.4) | 0.17% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS. This issue affects Specto CM: before 17032025. | |
| Analizada | Media (6.5) | 0.43% | — | Samsung Smart Touch Call | 2/12/2025 | 25/9/2026 | Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (5.1) | 0.31% | — | Xcally OmnichannelAI | 13/11/2025 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user… | |
| Aplazada | Media (4.3) | 0.27% | — | Callnowbutton Call NOW ButtonAI | 29/10/2025 | 17/6/2026 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (4.3) | 0.23% | — | Callnowbutton Call NOW ButtonAI | 29/10/2025 | 17/6/2026 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.5) | 0.17% | — | Remotecall Remote Support ProgramAI | 15/10/2025 | 17/6/2026 | RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.17% | — | Remotecall Remote Support ProgramAI | 15/10/2025 | 17/6/2026 | RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Aplazada | Alta (7.5) | 0.43% | — | Dynamically Display PostsAI | 15/10/2025 | 1/10/2026 | The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all versions up to, and including, 1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Callvision Healthcare Callvision Emergency CodeAI | 7/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0. | |
| Analizada | Baja (1.9) | 0.23% | — | Callapp | 20/7/2025 | 17/6/2026 | A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to improper export of android application components. It is possible to… | |
| Aplazada | Alta (7.1) | 0.21% | — | Plechevandrey Wp-recallAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tggfref WP-Recall allows Reflected XSS. This issue affects WP-Recall: from n/a through 16.26.14. | |
| Aplazada | Media (4.6) | 0.29% | — | Hexagon Hxgn Oncall Dispatch Advantage WEBAIHexagon Hxgn Oncall Dispatch Advantage MobileAI | 25/6/2025 | 17/6/2026 | Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code. | |
| Aplazada | Media (6.5) | 0.23% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.9. | |
| Aplazada | Media (5.9) | 0.26% | — | Truong Thanh ATP Call NOWAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Truong Thanh ATP Call Now atp-call-now allows Stored XSS.This issue affects ATP Call Now: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.38% | — | Plechevandrey Wp-recallAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14. | |
| Analizada | Crítica (9.8) | 0.43% | — | Avaya Call Management System | 10/6/2025 | 17/6/2026 | An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0. |