Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.47% | — | Codepassenger JOB Board ManagerAI | 17/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affects Job Board Manager for WordPress: from n/a through <= 1.0. | |
| Modificada | Crítica (9.8) | 0.55% | — | Eyecix Jobsearch WP JOB Board | 10/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9. | |
| Analizada | Crítica (9.8) | 0.52% | — | Eyecix Jobsearch WP JOB Board | 29/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3. | |
| Analizada | Alta (7.2) | 0.62% | — | Presstigers Simple JOB Board | 24/8/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP… | |
| Aplazada | Media (6.5) | 0.25% | — | Pickplugins JOB Board ManagerAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows Stored XSS.This issue affects Job Board Manager: from n/a through 2.1.57. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Presstigers Simple JOB Board | 9/4/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is… | |
| Analizada | Alta (7.5) | 0.60% | — | Eyecix Jobsearch WP JOB Board | 27/2/2024 | 17/6/2026 | The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server | |
| Analizada | Alta (7.5) | 0.55% | — | Eyecix Jobsearch WP JOB Board | 27/2/2024 | 17/6/2026 | The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address. | |
| Modificada | Media (5.3) | 0.91% | 💥 Exploit | Presstigers Simple JOB Board | 21/2/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password… | |
| Modificada | Alta (8.8) | 0.22% | — | Presstigers Simple JOB Board | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6. | |
| Modificada | Alta (8.8) | 0.31% | — | Presstigers Simple JOB Board | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions. | |
| Modificada | Crítica (9.8) | 0.54% | — | Smartweb Infotech JOB Board Project Smartweb Infotech JOB Board | 4/7/2023 | 17/6/2026 | A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulation of the argument filename leads to unrestricted upload. The attack may be launched remotely. The… | |
| Modificada | Media (4.3) | 0.70% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls. | |
| Modificada | Alta (8.8) | 1.2% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site. | |
| Modificada | Media (5.3) | 0.85% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin. | |
| Modificada | Media (6.1) | 0.53% | — | Bestwebsoft JOB Board | 2/5/2023 | 17/6/2026 | A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is… | |
| Modificada | Media (5.3) | 0.95% | — | Presstigers Simple JOB Board | 22/8/2022 | 17/6/2026 | The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing of uploaded resumes in certain configurations. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wpmanageninja Ninja JOB Board | 22/8/2022 | 17/6/2026 | The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Eyecix Jobsearch WP JOB Board | 4/4/2022 | 17/6/2026 | There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1. | |
| Modificada | Media (4.8) | 0.92% | — | Presstigers Simple JOB Board | 21/10/2021 | 17/6/2026 | The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject… | |
| Modificada | Media (4.8) | 0.91% | — | Perceptionsystem JOB Board Vanila | 15/10/2021 | 17/6/2026 | The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the psjb_exp_in and the psjb_curr_in parameters found in the ~/job-settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in… | |
| Modificada | Media (5.4) | 0.63% | — | Eyecix Jobsearch WP JOB Board | 12/7/2021 | 17/6/2026 | The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.92% | — | Presstigers Simple JOB Board | 13/8/2019 | 17/6/2026 | The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 Exploit | Nicephpscripts JOB Board Script | 29/10/2017 | 17/6/2026 | Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… |