Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Andreamarinucci Notification FOR TelegramAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions. | |
| Analizada | Media (5.1) | 0.16% | — | Qnap Notification Center | 10/6/2026 | 5/8/2026 | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later | |
| Aplazada | Crítica (9.1) | 0.21% | — | Amazon Simple Notification ServiceAIUseplunk PlunkAI | 8/5/2026 | 17/6/2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verifying the SNS signature, certificate, or topic ARN, meaning anyone can forge a valid-looking webhook request. This allows… | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Azure Monitor Action Group Notification System | 7/5/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (4.4) | 0.41% | — | Custom NEW User NotificationAI | 16/4/2026 | 17/6/2026 | The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on multiple settings fields including 'User Mail Subject', 'User From Name',… | |
| Aplazada | Baja (3.1) | 0.18% | — | Fluxcd Notification-controllerAI | 9/4/2026 | 17/6/2026 | Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This allows any valid Google-issued… | |
| Aplazada | Crítica (9.1) | 0.24% | — | Order Notification FOR WoocommerceAI | 1/4/2026 | 30/9/2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers. | |
| Aplazada | Media (5.4) | 0.29% | — | Cozyvision SMS Alert Order NotificationsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.9.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Admin Notices Hide Dashboard NotificationsAI | 25/2/2026 | 17/6/2026 | The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs… | |
| Aplazada | Media (5.3) | 0.30% | — | Wpdeveloper NotificationxAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper NotificationX notificationx allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NotificationX: from n/a through <= 3.2.1. | |
| Aplazada | Media (4.3) | 0.13% | — | Whatsiplus Scheduled Notification FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing nonce validation on the 'wsnfw_save_users_settings' AJAX action. This makes it possible for unauthenticated attackers to modify… | |
| Analizada | Media (6) | 0.19% | — | Tanium End-user Notifications | 9/2/2026 | 17/6/2026 | Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools. | |
| Aplazada | Media (4.9) | 0.38% | — | ALL Push Notification FOR WPAI | 4/2/2026 | 17/6/2026 | The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.34% | — | Webpushr-web-push-notificationsAI | 23/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in webpushr Webpushr webpushr-web-push-notifications allows Retrieve Embedded Sensitive Data.This issue affects Webpushr: from n/a through <= 4.38.0. | |
| Aplazada | Media (4.3) | 0.30% | — | Wpdeveloper NotificationxAI | 20/1/2026 | 17/6/2026 | The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.2) | 0.28% | — | Wpdeveloper NotificationxAI | 20/1/2026 | 17/6/2026 | The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to… | |
| Aplazada | Media (5.3) | 0.27% | — | Miniorange OTP Verification SMS NotificationAI | 10/1/2026 | 17/6/2026 | The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | Andreamarinucci Notification FOR TelegramAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notification for Telegram: from n/a through <= 3.5.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Gravitec.net WEB Push NotificationsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17. | |
| Aplazada | Media (6.1) | 0.26% | — | JabbernotificationAI | 5/12/2025 | 17/6/2026 | The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in all versions up to, and including, 0.99-RC2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.3) | 0.21% | — | Cozyvision SMS Alert Order NotificationsAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8. | |
| Aplazada | Alta (7.5) | 0.31% | — | Live Sales Notification FOR WoocommerceAI | 18/11/2025 | 17/6/2026 | The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes… | |
| Aplazada | Alta (7.2) | 0.50% | — | Qnap Notification CenterAI | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions:… | |
| Aplazada | Media (6.1) | 0.15% | — | TOP BAR NotificationAI | 4/11/2025 | 17/6/2026 | The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on th tbn_ajax_add() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject… |