Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.33% | — | Alex Zaytseff Multi Cryptocurrency PaymentsAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Multi CryptoCurrency Payments multi-crypto-currency-payment allows SQL Injection.This issue affects Multi CryptoCurrency Payments: from n/a through <= 2.0.7. | |
| Aplazada | Media (5.3) | 0.27% | — | Onthegosystems Woocommerce Multilingual & MulticurrencyAI | 9/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through <= 5.3.8. | |
| Aplazada | Media (6.5) | 0.38% | — | Blocksera Cryptocurrency Widgets PackAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack cryptocurrency-widgets-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets Pack: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpwham Currency Switcher FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce currency-switcher-for-woocommerce allows Stored XSS.This issue affects Currency Switcher for WooCommerce: from n/a through <= 0.0.7. | |
| Aplazada | Media (6.1) | 0.35% | — | Wpwham Currency Switcher FOR WoocommerceAI | 1/3/2025 | 17/6/2026 | The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.16.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wpfactory WP Currency Exchange RatesAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.9) | 0.41% | — | Falselight Cryptocurrency Price WidgetAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Cryptocurrency Price Widget cryptocurrency-price-widget allows Stored XSS.This issue affects Cryptocurrency Price Widget: from n/a through <= 1.2.3. | |
| Modificada | Crítica (9.8) | 0.93% | — | Coolplugins Cryptocurrency Widgets | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.2. | |
| Aplazada | Media (6.4) | 0.28% | — | Currency Converter Widget PROAI | 12/12/2024 | 17/6/2026 | The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Crítica (9.8) | 0.66% | — | Coolplugins Cryptocurrency Widgets FOR Elementor | 30/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through <=… | |
| Modificada | Media (5.4) | 0.31% | — | Glopium Ukrainian-currency | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Glopium Курс валют UAH ukrainian-currency allows Stored XSS.This issue affects Курс валют UAH: from n/a through <= 2.0. | |
| Aplazada | Alta (7.3) | 0.46% | — | Thefox FOX Currency Switcher ProfessionalAI | 9/11/2024 | 17/6/2026 | The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Modificada | Alta (8.8) | 0.36% | — | Onthegosystems Woocommerce Multilingual & Multicurrency | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through <= 5.3.6. | |
| Analizada | Alta (7.3) | 0.74% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 14/9/2024 | 17/6/2026 | The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the… | |
| Analizada | Media (6.1) | 0.31% | — | Coolplugins Cryptocurrency Widgets | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Reflected XSS.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.8.0. | |
| Aplazada | Media (6.4) | 0.27% | — | Master Currency WPAI | 27/7/2024 | 17/6/2026 | The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, 1.1.61 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.35% | — | Onthegosystems Woocommerce Multilingual & Multicurrency | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.4. | |
| Aplazada | Media (6.5) | 1.0% | — | Pluginus FOX - Currency Switcher Professional FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed… | |
| Modificada | Alta (7.2) | 0.54% | — | Onthegosystems Woocommerce Multilingual & Multicurrency | 18/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.3.1. | |
| Aplazada | Media (4.3) | 0.46% | — | Palscode Multi Currency FOR WoocommerceAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5. | |
| Aplazada | Media (4.3) | 0.20% | — | Tychesoftwares Currency PER Product FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Currency per Product for WooCommerce.This issue affects Currency per Product for WooCommerce: from n/a through 1.6.0. | |
| Modificada | Alta (8.8) | 0.24% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7. | |
| Modificada | Alta (8.8) | 0.24% | — | Pluginus Wordpress Currency Switcher | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. | |
| Aplazada | Media (6.5) | 0.34% | — | Currencyrate Exchange Rates WidgetAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Exchange Rates Widget allows Stored XSS.This issue affects Exchange Rates Widget: from n/a through 1.4.0. | |
| Aplazada | Media (6.5) | 0.33% | — | Currencyratetoday Crypto Converter WidgetAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.4. |