Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.29%—Olivethemes Olive ONE Click Demo Import9/6/202417/6/2026
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
ModificadaAlta (7.2)0.50%—Ocdi ONE Click Demo Import14/5/202417/6/2026
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.
AplazadaMedia (4.3)0.18%—Famethemes Fametheme Demo ImporterAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5.
ModificadaCrítica (9.8)0.58%—Olivethemes Olive ONE Click Demo Import20/3/202417/6/2026
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
ModificadaAlta (7.2)1.2%—Themely Theme Demo Import16/1/202417/6/2026
Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.
ModificadaAlta (7.2)0.80%—Olivethemes Olive ONE Click Demo Import20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
ModificadaAlta (7.2)0.80%—Themely Theme Demo Import20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import.This issue affects Theme Demo Import: from n/a through 1.1.1.
ModificadaAlta (7.2)1.1%—Postmagthemes Demo Import5/12/202217/6/2026
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.
ModificadaAlta (8.8)0.58%—Rarathemes Rara ONE Click Demo Import29/4/202217/6/2026
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
ModificadaAlta (8.1)0.48%—Accesspressthemes Access Demo Importer18/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media).
ModificadaMedia (6.5)0.49%—Accesspressthemes Access Demo Importer18/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin.
ModificadaAlta (7.2)1.7%—Ocdi ONE Click Demo Import11/4/202217/6/2026
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed
ModificadaAlta (7.2)1.4%—Catchplugins Catch Themes Demo Import7/3/202217/6/2026
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set…
ModificadaAlta (8.1)1.1%—Hashthemes Demo Importer1/11/202117/6/2026
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.
ModificadaAlta (7.2)56%💥 ExploitCatchplugins Catch Themes Demo Import21/10/202117/6/2026
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to…
ModificadaMedia (5.7)0.42%—Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+618/10/202117/6/2026
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before…
ModificadaAlta (8.8)1.7%—Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+3911/10/202117/6/2026
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the…
ModificadaAlta (8.8)0.65%—Themegrill Demo Importer5/5/202117/6/2026
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
ModificadaCrítica (9.1)4.1%💥 ExploitThemegrill Demo Importer5/5/202117/6/2026
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
Orbitaley — Vulnerabilidades