Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.37% | 💥 PoC | Acfextended Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities… | |
| Aplazada | Alta (8.1) | 0.23% | — | Advancedcustomfields Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Custom User Registration Fields FOR WoocommerceAI | 29/8/2026 | 1/9/2026 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in… | |
| Pendiente de análisis | Alta (8.1) | 0.20% | — | Drupal Edit In-place FieldAI | 25/8/2026 | 28/8/2026 | Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | |
| Aplazada | Alta (7.5) | 0.53% | — | Advanced Product FieldsAI | 22/8/2026 | 24/8/2026 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Dynamic Input Field GeneratorAI | 21/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Dynamic Input Field Generator Using Html CSS AND PHPAI | 21/8/2026 | 24/8/2026 | A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Form Processor Field HtmlareaAIPerl Html TidyAIPerl Locale MaketextAI | 13/8/2026 | 26/8/2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting… | |
| Aplazada | Media (6.5) | 0.22% | — | Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| Aplazada | Crítica (9.8) | 0.83% | 💥 PoC | Tychesoftwares Product Input Fields FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on… | |
| Aplazada | Media (4.3) | 0.27% | — | Advancedcustomfields Font Awesome FieldAI | 6/8/2026 | 12/8/2026 | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | |
| Aplazada | Crítica (10) | 0.57% | — | Custom FieldsAI | 5/8/2026 | 26/8/2026 | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover. | |
| Aplazada | Media (5.4) | 0.23% | — | Admin Columns FOR ACF FieldsAI | 1/8/2026 | 26/8/2026 | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (5.9) | 0.24% | — | Checkout Field EditorAI | 27/7/2026 | 27/7/2026 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | |
| Aplazada | Alta (8.1) | 0.41% | 💥 PoC | Custom Fields Account Registration FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator… | |
| Aplazada | Media (6.5) | 0.79% | — | Themehigh Checkout Field Editor FOR WoocommerceAI | 25/7/2026 | 27/7/2026 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary… | |
| Aplazada | Alta (8.8) | 0.51% | — | Product Addons AND Product Options With Custom FieldsAI | 22/7/2026 | 22/7/2026 | The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Field Service | 21/7/2026 | 3/8/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Aplazada | Media (6.4) | 0.32% | — | Smart Custom FieldsAI | 17/7/2026 | 17/7/2026 | The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and… | |
| Pendiente de análisis | Crítica (9.3) | 0.76% | — | Wago System I O FieldAI | 13/7/2026 | 13/7/2026 | Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote… | |
| Analizada | Alta (8.1) | 0.43% | — | Flag Attendance Field Project Flag Attendance Field | 10/7/2026 | 14/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. | |
| Analizada | Media (6.5) | 0.28% | — | Dopry Geolocation Field | 10/7/2026 | 6/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0. | |
| Analizada | Crítica (9.8) | 0.56% | — | Zroger Formatter Field | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. | |
| Aplazada | Media (6.5) | 0.47% | — | Blocks FOR ACF FieldsAI | 9/7/2026 | 9/7/2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic… |