Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.31% | — | Backupsheep Wordpress Backup PluginAI | 1/10/2026 | 1/10/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Aplazada | Alta (7.5) | 0.29% | — | Wordpress Backup MigrationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | |
| Aplazada | Alta (7.5) | 0.25% | — | Tipsandtricks-hq WP Express CheckoutAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | |
| Aplazada | Alta (8.5) | 0.26% | — | GamipressAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Wordpress Persistent Login Persistent LoginAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | ReactpressAI | 30/9/2026 | 30/9/2026 | The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.8) | 0.24% | — | Wpdeveloper EmbedpressAI | 30/9/2026 | 30/9/2026 | The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Pendiente de análisis | Media (6.3) | 0.16% | — | Expresslogic Netx Secure TLSAI | 29/9/2026 | 29/9/2026 | NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is… | |
| Pendiente de análisis | Media (6.9) | 0.25% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1)… | |
| Pendiente de análisis | Alta (8.7) | 0.31% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the… | |
| Pendiente de análisis | Alta (7.1) | 0.15% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len… | |
| Aplazada | Alta (7.5) | 0.36% | — | CompressAI | 29/9/2026 | 30/9/2026 | compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the… | |
| En análisis | Crítica (9.1) | 0.81% | 💥 PoC | Xhmikosr DecompressAI | 28/9/2026 | 30/9/2026 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a… | |
| Aplazada | Media (6.8) | 0.24% | — | Blubrry PowerpressAI | 27/9/2026 | 28/9/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.8) | 0.24% | — | Optima Express IDXAI | 27/9/2026 | 28/9/2026 | The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.3) | 0.18% | — | Optima Express IDXAI | 27/9/2026 | 28/9/2026 | The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected… | |
| Aplazada | Media (6.8) | 0.24% | — | Wpdeveloper EmbedpressAI | 27/9/2026 | 28/9/2026 | The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post. | |
| Aplazada | Baja (2.7) | 0.19% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending… | |
| Aplazada | Baja (2.7) | 0.17% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by… | |
| Aplazada | Alta (8.8) | 0.14% | — | MCP Server FOR WordpressAI | 26/9/2026 | 28/9/2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator… | |
| Aplazada | Alta (7.3) | 0.35% | — | Optima ExpressAI | 25/9/2026 | 25/9/2026 | The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain… | |
| Aplazada | Media (4.3) | 0.21% | — | Espressif ESP IDFAI | 24/9/2026 | 25/9/2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the received media buffer before validating that the packet layout contains the field. A paired BR/EDR audio source within… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | GimpAIGimpressionistAI | 24/9/2026 | 5/10/2026 | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious… | |
| Aplazada | Alta (8.1) | 0.64% | 💥 PoC | EthpressAI | 23/9/2026 | 24/9/2026 | The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a… |