Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.10% | — | Midnightbsd MportAI | 17/9/2026 | 18/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink… | |
| Aplazada | Media (5.8) | 0.12% | — | Midnightbsd MportAI | 17/9/2026 | 21/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local… | |
| Aplazada | Baja (2.7) | 0.32% | — | Comments Import ExportAI | 17/9/2026 | 18/9/2026 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP… | |
| Aplazada | Media (4.1) | 0.30% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site issue requests to internal hosts and services and read their responses. This is an… | |
| Aplazada | Media (6.8) | 0.43% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contributor to perform Stored XSS attacks which will trigger in the browser of a high… | |
| Aplazada | Media (6.8) | 0.39% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to perform SQL… | |
| Aplazada | Media (6.8) | 0.39% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by default and may also grant to lower roles, to perform SQL injection attacks. | |
| Aplazada | Media (6.8) | 0.47% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to disclose… | |
| Aplazada | Media (6.5) | 0.45% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary… | |
| Aplazada | Alta (8.8) | 0.73% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, including executable ones, on the server and achieve remote code execution. | |
| Aplazada | Alta (7.2) | 0.82% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution. | |
| Aplazada | Alta (7.2) | 0.82% | — | Vjinfotech WP Import Export LiteAI | 16/9/2026 | 17/9/2026 | The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on the server, leading to remote code execution. | |
| Aplazada | Alta (7.1) | 0.13% | — | Export Import Wpbakery Page BuilderAI | 12/9/2026 | 14/9/2026 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that… | |
| Pendiente de análisis | Alta (8.6) | 0.82% | — | Rarathemes Rara ONE Click Demo ImportAI | 9/9/2026 | 10/9/2026 | Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP files by passing a false value to wp_handle_upload() that disables WordPress core's file type validation checks across… | |
| Aplazada | Media (4.1) | 0.31% | — | Smackcoders WP Ultimate CSV ImporterAI | 29/8/2026 | 31/8/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | |
| Pendiente de análisis | Crítica (9.9) | 0.49% | — | Open Cluster Management Managedcluster Import ControllerAI | 17/8/2026 | 29/9/2026 | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Assimp Open Asset Import LibraryAI | 17/8/2026 | 20/8/2026 | A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may… | |
| Aplazada | Alta (7.5) | 0.43% | — | Importwp Import WPAI | 12/8/2026 | 26/8/2026 | The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email addresses, login names and roles. Exploitation… | |
| Aplazada | Media (5.3) | 0.33% | — | Akshaymenariya Export Import MenusAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | |
| Aplazada | Media (4.3) | 0.16% | — | Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI | 5/8/2026 | 26/8/2026 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Codection Import AND Export Users AND CustomersAI | 3/8/2026 | 26/8/2026 | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or… | |
| Aplazada | Media (4.9) | 0.47% | — | Codection Import AND Export Users AND CustomersAI | 3/8/2026 | 29/9/2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Pouco Import UsersAI | 2/8/2026 | 26/8/2026 | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and… | |
| Aplazada | Alta (7.2) | 0.50% | 💥 PoC | Demo ImportAI | 1/8/2026 | 26/8/2026 | The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the… | |
| Pendiente de análisis | Alta (7.7) | 0.57% | — | Kubevirt Containerized Data ImporterAI | 27/7/2026 | 21/9/2026 | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the… |