Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)2.8%💥 PoCWoody Code Snippets Insert Header Footer CodeAI15/6/202417/6/2026
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it…
ModificadaMedia (4.8)0.27%—Cm-wp Woody Code Snippets8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows Stored XSS.This issue affects Woody ad snippets: from n/a through 2.4.10.
AplazadaAlta (7.1)0.28%—WP Hive Events Rich Snippets FOR GoogleAI17/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.
AnalizadaCrítica (9.9)0.98%—Mainwp Code Snippets Extension17/5/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.
ModificadaMedia (5.3)0.48%—Pluginsandsnippets Simple Page Access Restriction8/2/202417/6/2026
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.
ModificadaAlta (8.8)0.30%—Code Snippets18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0.
ModificadaMedia (4.3)0.39%—Cm-wp Woody Code Snippets20/10/202317/6/2026
The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged…
ModificadaMedia (4.8)0.40%—Postsnippets Post Snippets8/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Postsnippets Post Snippets plugin <= 4.0.2 versions.
ModificadaMedia (4.8)0.37%—Itemprop WP FOR Serp/seo Rich Snippets Project Itemprop WP FOR Serp/seo Rich Snippets12/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Rolands Umbrovskis itemprop WP for SERP/SEO Rich snippets plugin <= 3.5.201706131 versions.
ModificadaMedia (5.4)0.38%—Mainwp Code Snippets Extension23/3/202317/6/2026
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension plugin <= 4.0.2 versions.
ModificadaMedia (6.1)0.81%—Codesnippets Code Snippets18/5/202217/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.
ModificadaMedia (6.1)0.39%—Code Snippets Extended Project Code Snippets Extended17/5/202217/6/2026
Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).
ModificadaMedia (5.4)0.40%—Code Snippets Extended Project Code Snippets Extended17/5/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets.
ModificadaAlta (8.8)0.96%—Code Snippets Extended Project Code Snippets Extended17/5/202217/6/2026
Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.
ModificadaCrítica (9.6)0.61%—Postsnippets Post Snippets28/2/202217/6/2026
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues
ModificadaMedia (6.1)2.3%💥 ExploitCodesnippets Code Snippets24/1/202217/6/2026
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)0.94%—WP Scrippets Project WP Scrippets10/9/202117/6/2026
The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.
ModificadaAlta (8.8)0.77%—Garfield Petshop Project Garfield Petshop9/10/202017/6/2026
A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
ModificadaAlta (8.8)12%💥 PoCCodesnippets Code Snippets28/1/202017/6/2026
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
ModificadaMedia (5.4)1.0%—Webcraftic Woody AD Snippets13/9/201917/6/2026
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
ModificadaAlta (8.8)18%💥 ExploitWebcraftic Woody AD Snippets3/9/201917/6/2026
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
ModificadaAlta (7.5)1.6%—Webcraftic Woody AD Snippets8/8/201917/6/2026
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
ModificadaMedia (5.4)0.27%—Animalcenter Light FOR Pets29/9/201417/6/2026
The Light for Pets (aka com.helenwoodward.light4pets) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Miniclip Mini Pets9/9/201417/6/2026
The Mini Pets (aka com.miniclip.animalshelter) application 2.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Playscape Pets FUN House9/9/201417/6/2026
The Pets Fun House (aka mominis.Generic_Android.Pets_Fun_House) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades