Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Creativewerkdesigns Export Order Product Customer Coupon FOR Woocommerce TO Google SheetsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets wpsyncsheets-woocommerce.This issue affects Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets: from n/a through <= 1.8.2. | |
| Analizada | Media (5.9) | 0.34% | — | Flickdevs Countdown Timer FOR Elementor | 26/2/2025 | 17/6/2026 | The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks. | |
| Analizada | Media (4.3) | 0.42% | — | Creativewerkdesigns Wpsyncsheets | 12/2/2025 | 17/6/2026 | The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsslwp_reset_settings() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.28% | — | Zackdesign Nextgen Cooliris GalleryAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen Cooliris Gallery nextgen-cooliris-gallery allows Stored XSS.This issue affects NextGen Cooliris Gallery: from n/a through <= 0.7. | |
| Aplazada | Media (5) | 0.28% | — | KDE ARKAI | 3/2/2025 | 17/6/2026 | libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive. | |
| Aplazada | Media (5.3) | 0.40% | — | ClickdesignsAI | 7/1/2025 | 17/6/2026 | The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the… | |
| Aplazada | Media (6.5) | 0.24% | — | Flickdevs Elementor Button PlusAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Elementor Button Plus fd-elementor-button-plus allows Stored XSS.This issue affects Elementor Button Plus: from n/a through <= 1.3.9. | |
| Aplazada | Media (6.5) | 0.24% | — | Flickdevs Countdown Timer FOR ElementorAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aezaz Shaikh Countdown Timer for Elementor countdown-timer-for-elementor allows Stored XSS.This issue affects Countdown Timer for Elementor: from n/a through <= 1.3.6. | |
| Analizada | Media (4.8) | 0.38% | — | Netfunkdesign Adbuddy+ (adblocker Detection) | 28/11/2024 | 17/6/2026 | The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Analizada | Media (5.3) | 0.55% | — | Avovkdesign Hide Links | 13/11/2024 | 17/6/2026 | The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site. | |
| Aplazada | Media (5.9) | 0.25% | — | KDE KmailAIKDE Kmail-account-wizardAI | 28/10/2024 | 17/6/2026 | ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to… | |
| Modificada | Media (6.1) | 0.39% | — | Duckdev Loggedin | 1/10/2024 | 17/6/2026 | The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (7.8) | 0.30% | — | KDE Plasma-workspace | 5/7/2024 | 17/6/2026 | KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to… | |
| Aplazada | Alta (7.1) | 0.55% | — | KDE LibksieveAI | 29/4/2024 | 17/6/2026 | In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value. | |
| Modificada | Baja (3.7) | 0.79% | — | KDE Plasma-workspace | 11/2/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path… | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Ndkdesign NDK Steppingpack | 25/10/2023 | 17/6/2026 | In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Media (5.4) | 0.62% | — | Duckdev 404 TO 301 | 7/6/2023 | 17/6/2026 | The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections. | |
| Modificada | Alta (7.8) | 0.25% | — | KDE Kcron | 26/2/2022 | 17/6/2026 | KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands. | |
| Modificada | Alta (7.8) | 0.89% | — | KDE KateKDE Ktexteditor | 11/2/2022 | 17/6/2026 | The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened… | |
| Modificada | Media (5.3) | 0.53% | — | KDE Kmail | 10/8/2021 | 17/6/2026 | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked. | |
| Modificada | Baja (3.7) | 0.79% | — | KDE Trojita | 10/8/2021 | 17/6/2026 | In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS. | |
| Modificada | Media (5.5) | 0.95% | — | KDE Kimageformats | 1/7/2021 | 17/6/2026 | KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE. | |
| Modificada | Media (6.5) | 0.61% | — | KDE Messagelib | 2/6/2021 | 17/6/2026 | KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be… | |
| Modificada | Alta (7.5) | 1.6% | — | KDE Discover | 20/3/2021 | 17/6/2026 | libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of the store.kde.org web site. (5.18.7 is also a fixed version.) | |
| Modificada | Crítica (9.8) | 4.3% | — | Sparkdevnetwork Rock RMS | 7/1/2021 | 17/6/2026 | Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain… |