Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.24%—Etruel Wpematico RSS Feed FetcherAI5/11/202517/6/2026
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations…
AplazadaMedia (5.9)0.41%—FetchmailAI4/10/202517/6/2026
In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.
AplazadaMedia (4.3)0.13%—Fetchdesigns Sign-up SheetsAI20/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Cross Site Request Forgery.This issue affects Sign-up Sheets: from n/a through <= 2.3.3.
AplazadaMedia (4.3)0.20%—Etruel Wpematico RSS Feed FetcherAI26/7/202517/6/2026
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for unauthenticated attackers to deactivate the plugin via a forged…
AnalizadaAlta (7.5)4.5%⚠ Explotación activaEslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+319/7/202517/6/2026
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
AplazadaMedia (6.5)0.32%—Fetchdesigns Sign-up SheetsAI15/4/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.0.1.
AplazadaAlta (7.5)0.28%—Freebsd FetchAI12/11/202417/6/2026
The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included…
AplazadaMedia (5.3)0.36%—Fetchdesigns Sign-up SheetsAI1/11/202417/6/2026
Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12.
AnalizadaMedia (6.1)0.39%—Fetchdesigns Sign-up Sheets4/9/202417/6/2026
The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.
ModificadaMedia (4)0.25%—Pjaudiomv Fetch JFT29/5/202417/6/2026
The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AplazadaMedia (4.3)0.20%—Fetchdesigns Sign-up SheetsAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1.
ModificadaAlta (8.8)0.25%—Fetchdesigns Sign-up Sheets3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions.
ModificadaMedia (6.1)0.52%—Twitter-post-fetcher Project Twitter-post-fetcher29/12/202217/6/2026
A vulnerability classified as problematic has been found in Twitter-Post-Fetcher up to 17.x. This affects an unknown part of the file js/twitterFetcher.js of the component Link Target Handler. The manipulation leads to use of web link to untrusted target with window.opener access. It is possible to initiate the attack…
ModificadaMedia (5.9)1.3%—Node-fetch Project Node-fetch1/8/202217/6/2026
Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.
ModificadaMedia (6.5)1.2%—Cross-fetch Project Cross-fetch15/4/202217/6/2026
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
ModificadaMedia (6.1)1.7%—Node-fetch Project Node-fetchSiemens Sinec INSDebian Linux16/1/202217/6/2026
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
ModificadaMedia (4.8)0.64%—Etruel Wpematico RSS Feed Fetcher1/11/202117/6/2026
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (5.9)0.92%—FetchmailFedoraproject Fedora30/8/202117/6/2026
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
ModificadaCrítica (9.1)2.6%—Freebsd Libfetch3/8/202117/6/2026
libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends…
ModificadaAlta (7.5)2.6%—FetchmailFedoraproject Fedora30/7/202117/6/2026
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform…
ModificadaAlta (8)1.3%—Fetchdesigns Sign-up Sheets12/7/202117/6/2026
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
ModificadaMedia (4.8)0.62%—Fetchdesigns Sign-up Sheets12/7/202117/6/2026
The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard
ModificadaMedia (5.3)1.7%—Node-fetch Project Node-fetch10/9/202017/6/2026
node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you…
ModificadaBaja (3.5)0.95%—Facebook Album Fetcher Project Facebook Album Fetcher21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.8)1.9%—Fetchmail21/12/201216/6/2026
Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and delayed delivery of inbound mail) via a crafted NTLM response that triggers an out-of-bounds read in the base64 decoder, or (2) obtain sensitive information from memory…