Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.21%—Verygoodplugins WP FusionAI7/9/20268/9/2026
The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)0.45%—Pickplugins ComboblocksAI5/9/20268/9/2026
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress,…
AplazadaMedia (6.4)0.42%—Fooplugins FoogalleryAI5/9/20268/9/2026
The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AplazadaMedia (5.3)0.29%—Kings Plugins MarketkingAI4/9/20267/9/2026
Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60.
AplazadaAlta (7.1)0.25%—Fullworksplugins Quick Event ManagerAI3/9/20264/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
AplazadaAlta (7.5)0.35%—Fullworksplugins Quick Event ManagerAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
AplazadaMedia (6.6)0.43%—Really-simple-plugins Really Simple SecurityAI30/8/202631/8/2026
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the…
AplazadaMedia (5.3)0.19%—Bplugins Document EmbedderAI27/8/202628/8/2026
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.
AplazadaMedia (5.4)0.29%—Weplugins WP MapsAI19/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.
AplazadaAlta (7.5)0.44%—Pickplugins User VerificationAI19/8/202626/8/2026
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them,…
AplazadaMedia (5.5)0.17%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI18/8/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second…
AplazadaMedia (5.5)0.29%—Linuxfabrik Monitoring PluginsAI18/8/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path…
AplazadaAlta (7.8)0.21%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI18/8/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins…
AplazadaAlta (7)0.18%—Linuxfabrik Monitoring PluginsAIDebian Apt-getAI18/8/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that…
AplazadaCrítica (9.3)0.40%—Gingerplugins Sticky Chat WidgetAI18/8/202620/8/2026
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
AplazadaMedia (5.3)0.16%—Fullworksplugins Quick Paypal PaymentsAI12/8/202626/8/2026
The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.
Pendiente de análisisAlta (7.1)0.21%—Zoom VDI ClientAIZoom VDI PluginsAI11/8/202628/8/2026
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
AplazadaMedia (5)0.27%—Plugins360 All-in-one Video GalleryAI10/8/202626/8/2026
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
Pendiente de análisisAlta (7.1)0.58%—Gstreamer Gst-plugins-uglyAI10/8/202616/9/2026
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads.…
Pendiente de análisisAlta (7.6)0.38%—Gstreamer Gst-plugins-badAI10/8/202618/9/2026
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to…
AplazadaMedia (6.5)0.41%—Weplugins WP MapsAI7/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
AplazadaAlta (8.8)0.53%—Weplugins WP MapsAI7/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
AplazadaMedia (5.3)0.16%—Fivestarplugins Five Star Restaurant ReservationsAI6/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending…
AplazadaAlta (7.5)0.40%—Paymentplugins Payment Plugins FOR PaypalAI6/8/202626/8/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
AplazadaMedia (6.5)0.17%—Plugins Garbage CollectorAI6/8/202612/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.