Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.30% | — | Gtalk Password FinderAI | 11/2/2026 | 17/6/2026 | GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.32% | — | Apkf Product KEY FinderAI | 11/2/2026 | 17/6/2026 | APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash. | |
| Aplazada | Media (4.4) | 0.12% | — | Qnap Qfinder PRO MACAIQnap Qsync MACAIQnap Qvpn Device Client MACAI | 2/1/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and… | |
| Modificada | Alta (8.1) | 0.53% | — | Ancorathemes Pathfinder | 18/12/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pathfinder pathfinder allows PHP Local File Inclusion.This issue affects Pathfinder: from n/a through <= 1.16. | |
| Analizada | Media (6.5) | 0.34% | — | Cksource Ckfinder | 5/12/2025 | 17/6/2026 | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Findall MembershipAI | 27/11/2025 | 17/6/2026 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user' and the… | |
| Aplazada | Crítica (9.8) | 0.35% | — | Findall ListingAI | 27/11/2025 | 17/6/2026 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (6.1) | 0.25% | 💥 PoC | Cksource Ckfinder | 14/11/2025 | 17/6/2026 | CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content. | |
| Analizada | Media (5.3) | 0.35% | — | Toastwebsites Find Unused Images | 11/11/2025 | 17/6/2026 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's… | |
| Aplazada | Alta (8.8) | 0.50% | — | Codesolz Better Find AND ReplaceAI | 8/11/2025 | 30/9/2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.22% | — | Codesolz Better Find AND ReplaceAI | 6/11/2025 | 17/6/2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access, to trigger… | |
| Aplazada | Alta (8.8) | 0.30% | — | Service Finder BookingsAI | 1/11/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.38% | — | Service Finder BookingsAI | 1/11/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers… | |
| Aplazada | Media (4.3) | 0.14% | — | Superstorefinder Super Store FinderAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5. | |
| Aplazada | Alta (7.1) | 0.23% | — | Wpinstinct Woo-vehicle-parts-finderAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpinstinct WOO Vehicle Parts FinderAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Object Injection.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. | |
| Aplazada | Alta (7.2) | 0.29% | — | Find AND Replace ContentAI | 15/10/2025 | 17/6/2026 | The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scripting and Arbitrary Content Replacement due to a missing capability check on the far_admin_ajax_fun() function in all versions up to, and including, 1.1. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.7) | 0.27% | — | Find ME ON WordpressAI | 8/10/2025 | 17/6/2026 | The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks | |
| Aplazada | Media (6.4) | 0.23% | — | Auto Bulb FinderAI | 3/10/2025 | 17/6/2026 | The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abf_vehicle' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.19% | — | Apustheme FindgoAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affects Findgo: from n/a through <= 1.3.55. | |
| Aplazada | Media (5.9) | 0.30% | — | Codesolz Better Find AND ReplaceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Stored XSS.This issue affects Better Find and Replace: from n/a through <= 1.7.6. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Service Finder BookingsAI | 19/9/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.43% | — | Service Finder SMS SystemAI | 19/9/2025 | 17/6/2026 | The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users. | |
| Analizada | Media (5.5) | 0.53% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php?q=result&searchfor=bycompany. This manipulation of the argument Search causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.46% | — | Campcodes Online JOB Finder System | 15/9/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform.php. The manipulation of the argument picture results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. |