Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.47% | — | Inisev Social Media & Share IconsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media & Share Icons: from n/a through 2.8.1. | |
| Aplazada | Media (4.3) | 0.42% | — | Cybernetikz Easy Social IconsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5. | |
| Analizada | Media (4.8) | 0.31% | — | Sanil Sticky Social Icons | 6/12/2024 | 17/6/2026 | The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.29% | — | Sanil Sticky Social IconsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanil Shakya Sticky Social Icons sticky-social-icons allows Stored XSS.This issue affects Sticky Social Icons: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Sistemasbebetter Bebetter Social IconsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sistemasBebetter BeBetter Social Icons bebetter-social-icons allows DOM-Based XSS.This issue affects BeBetter Social Icons: from n/a through <= 2.7. | |
| Aplazada | Media (6.6) | 0.32% | — | Michael Bourne Custom Icons FOR ElementorAI | 23/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor custom-icons-for-elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through <= 0.3.3. | |
| Analizada | Media (5.4) | 0.42% | — | Braginteractive Material Design Icons | 25/9/2024 | 17/6/2026 | The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, 0.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.26% | — | Wpai Elegant Themes Icons | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mayur Somani, threeroutes media Elegant Themes Icons allows Stored XSS.This issue affects Elegant Themes Icons: from n/a through 1.3. | |
| Modificada | Media (5.4) | 0.31% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Inisev Social Media & Share Icons allows Stored XSS.This issue affects Social Media & Share Icons: from n/a through 2.9.1. | |
| Aplazada | Alta (8.8) | 0.44% | — | AF IconsAI | 9/7/2024 | 17/6/2026 | The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.3. This is due to missing nonce validation in the 'afi_overview' function and missing file type validation in the 'upload_icons' function. This makes it… | |
| Aplazada | Media (5.4) | 0.36% | — | Hardik Chavada Sticky Social Media IconsAI | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1. | |
| Aplazada | Media (5.3) | 0.33% | — | Social Share PRO Social Share Icons AND Social Share ButtonsAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2. | |
| Modificada | Alta (8.8) | 1.5% | 💥 Exploit | Wpzoom Social Icons Widget | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15. | |
| Aplazada | Media (6.4) | 0.27% | — | WP Font Awesome Share IconsAI | 22/5/2024 | 17/6/2026 | The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpfai_social' shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.39% | — | Wpzoom Social Icons Widget | 21/5/2024 | 17/6/2026 | The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.4) | 0.37% | — | Themeisle Menu IconsAI | 16/5/2024 | 17/6/2026 | The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and… | |
| Aplazada | Alta (7.7) | 0.47% | — | Joris VAN Montfort JVM Rich Text IconsAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Joris van Montfort JVM rich text icons.This issue affects JVM rich text icons: from n/a through 1.2.6. | |
| Analizada | Media (5.9) | 0.40% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 17/4/2024 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Aplazada | Media (6.5) | 0.35% | — | Ghozylabinc WEB IconsAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab, Inc. Web Icons allows Stored XSS.This issue affects Web Icons: from n/a through 1.0.0.10. | |
| Modificada | Media (5.4) | 0.35% | — | Lordicon Animated Icons | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1. | |
| Aplazada | Media (6.5) | 0.34% | — | Ghozlab INC WEB IconsAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab, Inc. Web Icons allows Stored XSS.This issue affects Web Icons: from n/a through 1.0.0.10. | |
| Modificada | Alta (7.2) | 0.60% | — | Bplugins Icons Font Loader | 26/2/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4. | |
| Modificada | Media (5.4) | 0.33% | — | Themify Icons | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Icons allows Stored XSS.This issue affects Themify Icons: from n/a through 2.0.1. | |
| Modificada | Alta (8.8) | 0.61% | — | Jorisvm JVM Gutenberg Rich Text Icons | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3. | |
| Modificada | Media (4.8) | 0.35% | — | Freshlightlab Menu Image, Icons Made Easy | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Freshlight Lab Menu Image, Icons made easy allows Stored XSS.This issue affects Menu Image, Icons made easy: from n/a through 3.10. |