Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2604▼ 298 respecto a la semana anterior
Críticas / altas1343▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Automattic Jetpack Debug ToolsAI | 15/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1. | |
| Aplazada | Alta (7.2) | 0.29% | — | Bowo Debug LOG ManagerAI | 19/4/2025 | 17/6/2026 | The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.1) | 0.29% | — | Bowo Debug-log-managerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager debug-log-manager allows Stored XSS.This issue affects Debug Log Manager: from n/a through <= 2.3.4. | |
| Aplazada | Alta (7.1) | 0.29% | — | Plugins.club Enable WP Debug ToggleAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plugins.club WP_DEBUG Toggle enable-wp-debug-toggle allows Reflected XSS.This issue affects WP_DEBUG Toggle: from n/a through <= 1.1. | |
| Aplazada | Media (5.3) | 0.50% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through… | |
| Aplazada | Media (4.3) | 0.28% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a… | |
| Aplazada | Media (5.4) | 0.19% | — | Immunity DebuggerAI | 17/3/2025 | 17/6/2026 | Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, due to the lack of proper boundary checking. | |
| Aplazada | Alta (7.1) | 0.22% | — | Thorsten OTT Debug-bar-extenderAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thorsten Ott Debug-Bar-Extender debug-bar-extender allows Reflected XSS.This issue affects Debug-Bar-Extender: from n/a through <= 0.5. | |
| Aplazada | Media (5.5) | 0.27% | — | Immunity INC Immunity DebuggerAI | 13/2/2025 | 17/6/2026 | A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size. | |
| Aplazada | Media (4.3) | 0.40% | — | Eugen Bobrowski Debug-toolAI | 22/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Tool: from n/a through <= 2.2. | |
| Aplazada | Media (4.3) | 0.20% | — | Digitalzoomstudio Admin Debug Wordpress Enable DebugAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through <= 1.0.13. | |
| Aplazada | Media (6.5) | 0.23% | — | Debuggers Studio SaaspricingAI | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio SaasPricing saaspricing allows DOM-Based XSS.This issue affects SaasPricing: from n/a through <= 1.2.4. | |
| Aplazada | Crítica (10) | 0.46% | — | Eugen Bobrowski Debug-toolAI | 16/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through <= 2.2. | |
| Analizada | Media (5.4) | 0.16% | — | Intel Server Debug AND Provisioning Tool | 13/11/2024 | 17/6/2026 | Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.15% | — | Intel Server Debug AND Provisioning Tool | 13/11/2024 | 17/6/2026 | Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. | |
| Aplazada | Media (4.3) | 0.29% | — | Debug ToolAI | 9/11/2024 | 17/6/2026 | The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the info() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain information from phpinfo(). When… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Debug ToolAI | 9/11/2024 | 17/6/2026 | The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php… | |
| Analizada | Alta (8.8) | 0.36% | — | Bowo Debug LOG Manager | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1. | |
| Aplazada | Media (5.3) | 0.34% | — | Lukman Nakib Debug LOG Manger ToolAI | 3/6/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: from n/a through 1.4.5. | |
| Aplazada | Media (5.9) | 0.27% | — | Debug InfoAI | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debug Info allows Stored XSS.This issue affects Debug Info: from n/a through 1.3.10. | |
| Aplazada | Media (4.3) | 0.34% | — | Bowo Debug LOG ManagerAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1. | |
| Aplazada | Alta (7.1) | 0.33% | — | Bowo Debug LOG ManagerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS.This issue affects Debug Log Manager: from n/a through 2.3.1. | |
| Modificada | Alta (8.8) | 0.23% | — | Soninow Debug | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SoniNow Team Debug.This issue affects Debug: from n/a through 1.10. | |
| Modificada | Alta (7.5) | 0.65% | — | Bowo Debug LOG Manager | 8/1/2024 | 17/6/2026 | The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data | |
| Modificada | Alta (7.5) | 0.59% | — | Bowo Debug LOG Manager | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.0. |