Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Wordplus BP Better MessagesAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32. | |
| Modificada | Media (5.4) | 0.39% | — | Wordplus Better Messages | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss allows Stored XSS.This issue affects Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member,… | |
| Modificada | Alta (8.8) | 0.59% | — | Wordplus Better Messages | 19/11/2022 | 17/6/2026 | Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress. | |
| Modificada | Media (6.5) | 0.49% | — | Wordplus Better Messages | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress. | |
| Modificada | Alta (8.8) | 0.38% | — | Wordplus Better Messages | 23/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress. | |
| Modificada | Media (6.5) | 1.1% | — | Wordplus Better Messages | 23/8/2022 | 17/6/2026 | Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress. | |
| Modificada | Media (4.3) | 0.29% | — | Wordplus Better Messages | 20/7/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated. | |
| Modificada | Crítica (9.8) | 1.2% | — | KB Messages PHP Script Project KB Messages PHP Script | 13/7/2022 | 17/6/2026 | A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.55% | — | Private Messages Project Private Messages | 15/6/2022 | 17/6/2026 | Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress. | |
| Modificada | Media (4.3) | 0.40% | — | Private Messages Project Private Messages | 15/6/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages. | |
| Modificada | Crítica (9.8) | 1.5% | — | Contact-form-with-messages-entry-management Project Contact-form-with-messages-entry-management | 2/6/2022 | 17/6/2026 | EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Alta (8.8) | 0.73% | — | Wordplus Better Messages | 1/11/2021 | 17/6/2026 | The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread,… | |
| Modificada | Media (6.1) | 0.94% | — | Wordplus Better Messages | 1/11/2021 | 17/6/2026 | The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.41% | — | Light Messages Project Light Messages | 16/8/2021 | 17/6/2026 | The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting… | |
| Modificada | Crítica (9.8) | 4.5% | — | IBM IOT MessagesightIBM Watson IOT Platform - Message Gateway | 28/1/2020 | 17/6/2026 | IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute… | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (8.8) | 2.3% | — | IBM Messagesight | 1/7/2016 | 17/6/2026 | JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors. | |
| Modificada | Baja (3.5) | 2.4% | 💥 Exploit | Amtelco Misecuremessages | 6/5/2014 | 17/6/2026 | Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request. | |
| Modificada | Media (4.6) | 1.1% | — | IBM Messagesight JMS ClientIBM Messagesight | 15/4/2014 | 17/6/2026 | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring. | |
| Modificada | Media (4.3) | 1.4% | — | IBM Messagesight JMS ClientIBM Messagesight | 15/4/2014 | 17/6/2026 | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Messagesight JMS ClientIBM Messagesight | 15/4/2014 | 17/6/2026 | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Messagesight JMS ClientIBM Messagesight | 15/4/2014 | 17/6/2026 | The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade. | |
| Modificada | Media (5) | 1.8% | — | Amtelco Misecuremessages | 15/4/2014 | 17/6/2026 | Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application. |