Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.41% | — | Jose Mortellaro Content NO CacheAI | 27/6/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.This issue affects Content No Cache: from n/a through <= 0.1.4. | |
| Aplazada | Alta (7.1) | 0.38% | — | Jose Conti Link ShieldAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Conti Link Shield link-shield allows Stored XSS.This issue affects Link Shield: from n/a through <= 0.5.4. | |
| Aplazada | Media (4.3) | 0.42% | — | Jose Mortellaro Specific Content FOR MobileAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Jose Mortellaro Specific Content For Mobile specific-content-for-mobile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Specific Content For Mobile: from n/a through <= 0.5.3. | |
| Aplazada | Media (6.6) | 0.40% | — | GO JoseAI | 24/2/2025 | 17/6/2026 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE… | |
| Aplazada | Media (4.3) | 0.16% | — | Josesan Woo-recargo-de-equivalenciaAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in josesan WooCommerce Recargo de Equivalencia woo-recargo-de-equivalencia allows Cross Site Request Forgery.This issue affects WooCommerce Recargo de Equivalencia: from n/a through <= 1.6.24. | |
| Aplazada | Media (4.3) | 0.42% | — | Jose Mortellaro Freesoul Deactivate PluginsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Freesoul Deactivate Plugins – Plugin manager and cleanup: from n/a through 2.1.3. | |
| Aplazada | Media (5.7) | 0.55% | — | DjoserAI | 13/12/2024 | 17/6/2026 | Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom authentication checks such as two-factor… | |
| Aplazada | Media (4.3) | 0.43% | — | Josevega Display Custom Fields IN THE Frontend Post AND User Profile FieldsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jose Vega Display custom fields in the frontend – Post and User Profile Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display custom fields in the frontend – Post and User Profile Fields: from n/a through 1.2.0. | |
| Aplazada | Alta (7.5) | 0.68% | — | Joseph C Dolson MY TicketsAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11. | |
| Analizada | Media (5.3) | 0.78% | — | Python-jose Project Python-jose | 26/4/2024 | 17/6/2026 | python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319. | |
| Analizada | Media (6.5) | 0.31% | — | Python-jose Project Python-jose | 26/4/2024 | 17/6/2026 | python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. | |
| Aplazada | Media (5.9) | 0.34% | — | Joby Joseph WP Twitter Mega FAN BOX WidgetAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joby Joseph WP Twitter Mega Fan Box Widget allows Stored XSS.This issue affects WP Twitter Mega Fan Box Widget : from n/a through 1.0. | |
| Modificada | Alta (7.5) | 1.4% | — | Latchset JoseFedoraproject Fedora | 20/3/2024 | 17/6/2026 | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | |
| Aplazada | Alta (7.1) | 0.39% | — | Jose Mortellaro Specific Content FOR Mobile Customize THE Mobile Version Without RedirectionsAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Mortellaro Specific Content For Mobile – Customize the mobile version without redirections allows Reflected XSS.This issue affects Specific Content For Mobile – Customize the mobile version without redirections:… | |
| Aplazada | Media (5.3) | 0.89% | — | Erlang-joseAI | 19/3/2024 | 17/6/2026 | erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header. | |
| Aplazada | Media (6.5) | 0.33% | — | Joseph C Dolson MY CalendarAI | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23. | |
| Analizada | Media (4.3) | 2.0% | — | Go-jose Project Go-joseFedoraproject Fedora | 9/3/2024 | 17/6/2026 | Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data… | |
| Analizada | Media (5.9) | 2.1% | — | Jose Project JoseFedoraproject Fedora | 9/3/2024 | 17/6/2026 | jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has been identified in the JSON Web Encryption (JWE) decryption interfaces,… | |
| Analizada | Media (4.8) | 0.42% | — | Josephlopreste Restaurant Solutions - Checklist | 29/2/2024 | 17/6/2026 | The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web… | |
| Modificada | Media (6.5) | 0.87% | — | Jose4j Project Jose4j | 29/2/2024 | 17/6/2026 | The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | |
| Analizada | Alta (7.5) | 0.82% | — | Dvsekhvalnov Jose2go | 29/2/2024 | 17/6/2026 | The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | |
| Modificada | Alta (7.5) | 0.81% | — | Connect2id Nimbus Jose+jwt | 11/2/2024 | 17/6/2026 | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component. | |
| Modificada | Media (4.3) | 0.47% | — | Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.29% | — | Joselazo Delete Usermeta | 22/11/2023 | 17/6/2026 | The Delete Usermeta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing nonce validation on the delumet_options_page() function. This makes it possible for unauthenticated attackers to remove user meta for arbitrary users via a forged request… | |
| Modificada | Alta (7.5) | 0.64% | — | Jose4j Project Jose4j | 25/10/2023 | 17/6/2026 | jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less. |