Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 2.8% | 💥 PoC | Woody Code Snippets Insert Header Footer CodeAI | 15/6/2024 | 17/6/2026 | The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it… | |
| Modificada | Media (4.8) | 0.27% | — | Cm-wp Woody Code Snippets | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows Stored XSS.This issue affects Woody ad snippets: from n/a through 2.4.10. | |
| Aplazada | Alta (7.1) | 0.28% | — | WP Hive Events Rich Snippets FOR GoogleAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8. | |
| Analizada | Crítica (9.9) | 0.98% | — | Mainwp Code Snippets Extension | 17/5/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2. | |
| Modificada | Media (5.3) | 0.48% | — | Pluginsandsnippets Simple Page Access Restriction | 8/2/2024 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content. | |
| Modificada | Alta (8.8) | 0.30% | — | Code Snippets | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0. | |
| Modificada | Media (4.3) | 0.39% | — | Cm-wp Woody Code Snippets | 20/10/2023 | 17/6/2026 | The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged… | |
| Modificada | Media (4.8) | 0.40% | — | Postsnippets Post Snippets | 8/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Postsnippets Post Snippets plugin <= 4.0.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Itemprop WP FOR Serp/seo Rich Snippets Project Itemprop WP FOR Serp/seo Rich Snippets | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Rolands Umbrovskis itemprop WP for SERP/SEO Rich snippets plugin <= 3.5.201706131 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Mainwp Code Snippets Extension | 23/3/2023 | 17/6/2026 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension plugin <= 4.0.2 versions. | |
| Modificada | Media (6.1) | 0.81% | — | Codesnippets Code Snippets | 18/5/2022 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter. | |
| Modificada | Media (6.1) | 0.39% | — | Code Snippets Extended Project Code Snippets Extended | 17/5/2022 | 17/6/2026 | Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code). | |
| Modificada | Media (5.4) | 0.40% | — | Code Snippets Extended Project Code Snippets Extended | 17/5/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets. | |
| Modificada | Alta (8.8) | 0.96% | — | Code Snippets Extended Project Code Snippets Extended | 17/5/2022 | 17/6/2026 | Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery. | |
| Modificada | Crítica (9.6) | 0.61% | — | Postsnippets Post Snippets | 28/2/2022 | 17/6/2026 | The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Codesnippets Code Snippets | 24/1/2022 | 17/6/2026 | The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.94% | — | WP Scrippets Project WP Scrippets | 10/9/2021 | 17/6/2026 | The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1. | |
| Modificada | Alta (8.8) | 0.77% | — | Garfield Petshop Project Garfield Petshop | 9/10/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts. | |
| Modificada | Alta (8.8) | 12% | 💥 PoC | Codesnippets Code Snippets | 28/1/2020 | 17/6/2026 | The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu. | |
| Modificada | Media (5.4) | 1.0% | — | Webcraftic Woody AD Snippets | 13/9/2019 | 17/6/2026 | The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter. | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Webcraftic Woody AD Snippets | 3/9/2019 | 17/6/2026 | admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution. | |
| Modificada | Alta (7.5) | 1.6% | — | Webcraftic Woody AD Snippets | 8/8/2019 | 17/6/2026 | admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion. | |
| Modificada | Media (5.4) | 0.27% | — | Animalcenter Light FOR Pets | 29/9/2014 | 17/6/2026 | The Light for Pets (aka com.helenwoodward.light4pets) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Miniclip Mini Pets | 9/9/2014 | 17/6/2026 | The Mini Pets (aka com.miniclip.animalshelter) application 2.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Playscape Pets FUN House | 9/9/2014 | 17/6/2026 | The Pets Fun House (aka mominis.Generic_Android.Pets_Fun_House) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |