Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.40%—Tipsandtricks-hq WP Estore12/8/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (6.5)0.45%—Tipsandtricks-hq WP Estore12/8/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.42%—Tipsandtricks-hq WP Estore15/7/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (8.8)0.37%—Tipsandtricks-hq WP Estore15/7/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
ModificadaMedia (6.1)0.34%—Tipsandtricks-hq WP Estore15/7/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.32%—Tipsandtricks-hq WP Estore15/7/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.33%—Tipsandtricks-hq WP Estore15/7/202417/6/2026
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
AnalizadaMedia (5.3)0.56%—Wpbackitup Backup AND Restore Wordpress26/3/202417/6/2026
The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data
ModificadaMedia (6.5)0.57%—Estore-wss Payment EX1/2/202417/6/2026
Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise using Payment EX.
ModificadaMedia (5.5)0.12%—Google Cloud Firestore4/12/202317/6/2026
A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue
ModificadaMedia (4.8)0.37%—Wow-estore Button Generator - Easily Button Builder22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.
ModificadaMedia (5.4)0.47%—Onlinestorekit Oneclick Chat TO Order23/1/202317/6/2026
The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaAlta (8.8)0.89%—IBM Spectrum Protect Plus Container Backup AND Restore30/6/202217/6/2026
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By…
ModificadaMedia (4.9)1.0%—Wow-estore Herd Effects20/5/202217/6/2026
Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.
ModificadaAlta (7.2)1.0%—Wow-estore Popup BOX18/5/202217/6/2026
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.
ModificadaMedia (4.3)0.47%—Wow-estore Float Menu21/2/202217/6/2026
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack
ModificadaAlta (8.8)1.4%—Wow-estore Side Menu30/8/202117/6/2026
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue
ModificadaAlta (7.2)1.6%—Wow-estore Side Menu9/8/202117/6/2026
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.
ModificadaAlta (7.2)1.6%—Wow-estore Side Menu14/6/202117/6/2026
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue
ModificadaAlta (7.1)0.58%—Cloudfoundry Bosh Backup AND Restore24/4/201917/6/2026
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in…
ModificadaCrítica (9.8)0.69%—NQ Contacts Backup & Restore29/10/201717/6/2026
In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it for further attacks where only the hash…
ModificadaAlta (7.5)0.51%—NQ Contacts Backup & Restore29/10/201717/6/2026
In the "NQ Contacts Backup & Restore" application 1.1 for Android, DES encryption with a static key is used to secure transmitted contact data. This makes it easier for remote attackers to obtain cleartext information by sniffing the network.
ModificadaAlta (7.8)0.13%—NQ Contacts Backup & Restore29/10/201717/6/2026
In the "NQ Contacts Backup & Restore" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a static RC4 key, an attacker can gain access to user credentials more easily by leveraging access to the preferences XML file.
ModificadaMedia (5.5)0.38%—Criu Checkpoint/restore IN UserspaceOpensuse7/6/201617/6/2026
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
ModificadaAlta (7.8)0.39%—OpensuseCriu Checkpoint/restore IN Userspace7/6/201617/6/2026
The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.
Orbitaley — Vulnerabilidades