Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.27% | — | Auburnforest BlogmentorAI | 19/6/2024 | 17/6/2026 | The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagination_style’ parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.50% | — | Kitforest Better Elementor Addons | 4/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elementor Addons allows PHP Local File Inclusion.This issue affects Better Elementor Addons: from n/a through 1.4.1. | |
| Modificada | Media (5.4) | 0.41% | — | Kitforest Better Elementor Addons | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons better-elementor-addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.4.4. | |
| Aplazada | Media (5.9) | 0.34% | — | Meks Themeforest Smart WidgetAI | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks ThemeForest Smart Widget allows Stored XSS.This issue affects Meks ThemeForest Smart Widget: from n/a through 1.5. | |
| Modificada | Media (5.4) | 0.33% | — | Kitforest Better Elementor Addons | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.3.7. | |
| Modificada | Media (5.4) | 0.40% | — | Kitforest Better Elementor Addons | 29/3/2024 | 17/6/2026 | The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL values in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (6.1) | 0.42% | — | Inforest Communications SupercaliAI | 5/3/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page. | |
| Modificada | Alta (7.5) | 0.66% | — | Rymcu Forest | 13/1/2024 | 17/6/2026 | An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file. | |
| Modificada | Crítica (9.8) | 0.91% | — | Forestblog Project Forestblog | 17/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img of the component Image Upload Handler. The manipulation of the argument filename leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (5.3) | 1.1% | — | Aquaforest Tiff Server | 30/11/2023 | 17/6/2026 | The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or… | |
| Modificada | Alta (8.8) | 0.44% | — | Mekshq Meks Audio PlayerMekshq Meks Easy ADS WidgetMekshq Meks Easy MapsMekshq Meks Easy Photo Feed Widget+6 | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the… | |
| Modificada | Alta (8.8) | 0.82% | — | Riverforest-wp Media From FTP | 4/9/2023 | 17/6/2026 | The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases. | |
| Modificada | Media (4.3) | 0.55% | — | Riverforest-wp Simple Blog Card | 30/8/2023 | 17/6/2026 | The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones | |
| Modificada | Media (5.4) | 0.43% | — | Riverforest-wp Simple Blog Card | 30/8/2023 | 17/6/2026 | The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.48% | — | Riverforest-wp ALL Users Messenger | 30/8/2023 | 17/6/2026 | The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger. | |
| Modificada | Media (6.1) | 0.56% | — | Forestblog Project Forestblog | 16/4/2022 | 17/6/2026 | ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar. | |
| Modificada | Media (6.1) | 0.59% | — | Forestblog Project Forestblog | 25/1/2022 | 17/6/2026 | A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box. | |
| Modificada | Crítica (9.8) | 1.2% | — | Forestblog Project Forestblog | 25/1/2022 | 17/6/2026 | In ForestBlog, as of 2021-12-28, File upload can bypass verification. | |
| Modificada | Alta (8.8) | 0.55% | — | Forestblog Project Forestblog | 11/5/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges. | |
| Modificada | Alta (7.5) | 1.8% | — | Aquaforest Tiff Server | 18/3/2020 | 17/6/2026 | Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. | |
| Modificada | Alta (7.5) | 1.4% | — | Aquaforest Tiff Server | 18/3/2020 | 17/6/2026 | Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. | |
| Modificada | Media (5.3) | 1.6% | — | Aquaforest Tiff Server | 18/3/2020 | 17/6/2026 | Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx. | |
| Modificada | Media (5.4) | 0.27% | — | Forestarea Forest Area FCU Mobile | 19/10/2014 | 17/6/2026 | The Forest Area FCU Mobile (aka com.metova.cuae.fafcu) application 1.0.29 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Woodforest Mobile Banking | 2/10/2014 | 17/6/2026 | The Woodforest Mobile Banking (aka com.woodforest) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Socialknowledge Forest River Forums | 2/10/2014 | 17/6/2026 | The Forest River Forums (aka com.socialknowledge.forestriverforums) application 3.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |