Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
258 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Extendthemes Mesmerize CompanionAIExtendthemes MesmerizeAI | 19/2/2026 | 17/6/2026 | The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the "openPageInCustomizer" and "openPageInDefaultEditor" functions in all versions up to, and including, 1.6.158. This makes it possible for authenticated attackers - with… | |
| Aplazada | Media (4.4) | 0.28% | — | Extended Random Number GeneratorAI | 4/2/2026 | 17/6/2026 | The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Crítica (9.5) | 1.5% | — | Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+2 | 30/1/2026 | 17/6/2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects | |
| Aplazada | Crítica (9.8) | 1.5% | — | Acfextended Advanced Custom Fields ExtendedAI | 20/1/2026 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Media (5.4) | 0.19% | — | Extendons WP ScraperAI | 31/12/2025 | 23/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through <= 1.0.7. | |
| Modificada | Alta (8.8) | 0.21% | — | Extendthemes Vireo | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24. | |
| Aplazada | Media (6.4) | 0.29% | — | Extendthemes Colibri Page BuilderAI | 19/12/2025 | 17/6/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.22% | — | Extendthemes Colibri Page BuilderAI | 13/12/2025 | 7/10/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (7.2) | 1.7% | — | Fortinet Fortiextender Firmware | 9/12/2025 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via… | |
| Aplazada | Media (6.5) | 0.19% | — | GET Bowtied Shopkeeper ExtenderAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0. | |
| Aplazada | Crítica (9.8) | 68% | 💥 Exploit | Acfextended Advanced Custom Fields ExtendedAI | 3/12/2025 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.15% | — | Nextend Social Login AND RegisterAI | 28/11/2025 | 8/10/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login… | |
| Modificada | Alta (7.8) | 0.15% | — | Fortinet Fortiextender Firmware | 18/11/2025 | 17/6/2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI… | |
| Analizada | Media (5.5) | 0.16% | — | Fortinet Fortiextender Firmware | 18/11/2025 | 17/6/2026 | A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands. | |
| Aplazada | Alta (8.8) | 0.39% | — | Extendons Woocommerce Registration FieldsAI | 22/10/2025 | 8/10/2026 | Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Privilege Escalation.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a through <= 3.2.3. | |
| Modificada | Media (5.9) | 0.22% | — | Extendthemes Colibri Page Builder | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through < 1.0.334. | |
| Aplazada | Alta (7.1) | 0.28% | — | Extendons Woocommerce Registration Fields PluginAI | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Reflected XSS.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a… | |
| Aplazada | Media (6.4) | 0.23% | — | Extendthemes Colibri Page BuilderAI | 11/10/2025 | 17/6/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 0.68% | — | IBM Transformation Extender Advanced | 6/10/2025 | 17/6/2026 | IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Analizada | Media (6.2) | 0.11% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls. | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Analizada | Alta (8.8) | 0.22% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (4.4) | 0.12% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user. | |
| Aplazada | Media (6.4) | 0.20% | — | Widget Options ExtendedAI | 23/9/2025 | 17/6/2026 | The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sidebar' shortcode in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.13% | — | Extendyourweb Horizontal SliderAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER horizontal-slider allows Stored XSS.This issue affects HORIZONTAL SLIDER: from n/a through <= 2.4. |