Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.75% | — | Iqonic Wpbookit | 9/5/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it… | |
| Aplazada | Crítica (9.8) | 54% | 💥 Exploit | Brainstormforce OttokitAIBrainstormforce SuretriggersAI | 1/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | |
| Analizada | Alta (8.8) | 0.41% | — | Carlinkit Autokit | 23/4/2025 | 17/6/2026 | CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8) | 0.25% | — | Carlinkit Autokit | 23/4/2025 | 17/6/2026 | CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Although authentication is required to exploit this vulnerability,… | |
| Analizada | Media (6.8) | 0.21% | — | Carlinkit Autokit | 23/4/2025 | 17/6/2026 | CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.8) | 0.19% | — | Carlinkit Autokit | 23/4/2025 | 17/6/2026 | CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of CarlinKit CPC200-CCPA devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Media (5.3) | 0.45% | — | Iqonic Wpbookit | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7. | |
| Modificada | Media (6.1) | 0.14% | — | Iqonic Wpbookit | 10/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.78% | — | Octokit RequestAI | 14/2/2025 | 17/6/2026 | @octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in version 1.0.0 and prior to versions 9.2.1 and 8.4.1, the regular expression `/<([^>]+)>; rel="deprecation"/` used to match the `link` header in HTTP responses is vulnerable to a ReDoS (Regular… | |
| Aplazada | Media (5.3) | 0.63% | — | Octokit Request-errorAI | 14/2/2025 | 17/6/2026 | @octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long sequence of spaces… | |
| Aplazada | Media (5.3) | 0.63% | — | Octokit Plugin-paginate-restAI | 14/2/2025 | 17/6/2026 | @octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link`… | |
| Aplazada | Media (5.3) | 0.63% | — | Octokit EndpointAI | 14/2/2025 | 17/6/2026 | @octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to… | |
| Analizada | Crítica (9.8) | 1.1% | — | Iqonic Wpbookit | 25/1/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Analizada | Crítica (9.8) | 0.66% | — | Iqonic Wpbookit | 9/1/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 0.63% | — | Iqonic Wpbookit | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from n/a through <= 1.6.0. | |
| Modificada | Crítica (9.8) | 0.51% | — | Jackzhu Photokit | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Shell to a Web Server.This issue affects photokit: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Promokit PK IsotopeAIPrestashopAI | 24/6/2024 | 17/6/2026 | SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods. | |
| Aplazada | Alta (7.5) | 0.38% | — | Promokit PK ThemesettingsAIPrestashopAI | 24/6/2024 | 17/6/2026 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal… | |
| Aplazada | Alta (7.5) | 10% | — | Promokit Facebook ModuleAIPrestashopAI | 19/6/2024 | 17/6/2026 | In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Crítica (9.8) | 0.56% | — | Promokit PK Themesettings | 19/6/2024 | 17/6/2026 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Aplazada | Media (6.5) | 0.48% | — | Theeventscalendar BookitAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0. | |
| Modificada | Alta (7.2) | 0.53% | — | Stylemixthemes Bookit | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Booking Calendar | Appointment Booking | BookIt.This issue affects Booking Calendar | Appointment Booking | BookIt: from n/a through 2.4.3. | |
| Modificada | Alta (7.5) | 0.73% | — | Octokit APPOctokitOctokit WebhooksProbot | 15/12/2023 | 17/6/2026 | octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the @octokit/webhooks library because the error can be undefined in some cases. The resulting request was found to cause an… | |
| Modificada | Crítica (9.8) | 3.2% | — | Geokit-rails | 6/10/2023 | 17/6/2026 | Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system. | |
| Modificada | Crítica (9.8) | 1.9% | — | Stylemixthemes Bookit | 30/6/2023 | 17/6/2026 | The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on… |