Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.43%—Recipepress ReloadedAI21/11/202417/6/2026
The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaMedia (5.3)0.46%—Rems Profile Registration Without Reload/refresh10/10/202417/6/2026
A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/address/company_name/job_title/jobDescriptionparameter leads to…
AnalizadaMedia (5.3)0.54%—Rems Profile Registration Without Reload/refresh23/9/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0. This affects an unknown part of the file del.php of the component GET Parameter Handler. The manipulation of the argument list leads to sql injection. It is possible to initiate the attack remotely.…
AnalizadaMedia (5.3)0.46%—Rems Profile Registration Without Reload/refresh23/9/202417/6/2026
A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add.php of the component Registration Form. The manipulation of the argument full_name leads to cross site scripting. The…
AnalizadaMedia (5.4)0.30%—Wp-brandtheme Preloader Plus7/9/202417/6/2026
The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
AplazadaMedia (4.3)0.40%—Comment Images ReloadedAI9/7/202417/6/2026
The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary…
AplazadaMedia (5.3)0.51%—Webtoffee Preloader FOR WebsiteAI11/6/202417/6/2026
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2.
ModificadaAlta (7.5)0.51%—Wpkube Subscribe TO Comments Reloaded10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
AplazadaAlta (7.1)0.23%—Sverde1 Watermark ReloadedAI16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sverde1 Watermark RELOADED watermark-reloaded allows Cross Site Request Forgery.This issue affects Watermark RELOADED: from n/a through <= 1.3.5.
AnalizadaCrítica (9.8)0.69%—Remyandrade Crud Without Page Reload/refresh12/3/202417/6/2026
A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add_user.php. The manipulation of the argument city leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.1)0.57%—Remyandrade Crud Without Page Reload/refresh3/2/202417/6/2026
A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file fetch_data.php. The manipulation of the argument username/city leads to cross site scripting. The attack may be launched remotely. The exploit has…
ModificadaMedia (5.4)0.43%—Limitloginattempts Limit Login Attempts Reloaded11/1/202417/6/2026
The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (4.3)0.45%—Limitloginattempts Limit Login Attempts Reloaded27/11/202317/6/2026
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
ModificadaAlta (8.8)0.29%—Nkb-bd Preloader Matrix18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lukman Nakib Preloader Matrix.This issue affects Preloader Matrix: from n/a through 2.0.1.
ModificadaAlta (7.8)0.20%—Lenovo Preload Directory8/11/202317/6/2026
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.
ModificadaAlta (8.8)0.21%—Thefreewindows Auto Limit Posts Reloaded6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in TheFreeWindows Auto Limit Posts Reloaded plugin <= 2.5 versions.
ModificadaMedia (5.4)0.46%—Wpexperts User Avatar-reloaded16/10/202317/6/2026
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
ModificadaMedia (6.1)1.0%—Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaMedia (4.8)0.39%—Catchsquare WP Smart Preloader30/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catchsquare WP Smart Preloader plugin <= 1.15 versions.
ModificadaMedia (5.4)0.47%—Wp-table Reloaded Project Wp-table Reloaded9/1/202317/6/2026
The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such…
ModificadaMedia (6.5)0.52%—Jenkins Matrix Reloaded30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.
ModificadaMedia (5.4)0.60%—Jenkins Matrix Reloaded30/6/202217/6/2026
Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
ModificadaMedia (5.4)0.39%—Wpkube Subscribe TO Comments Reloaded29/4/202217/6/2026
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications…
ModificadaCrítica (9.6)2.2%—PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial Project PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial24/1/202217/6/2026
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
ModificadaAlta (8.8)54%—Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+2218/1/202217/6/2026
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.