Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.43% | — | Recipepress ReloadedAI | 21/11/2024 | 17/6/2026 | The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (5.3) | 0.46% | — | Rems Profile Registration Without Reload/refresh | 10/10/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/address/company_name/job_title/jobDescriptionparameter leads to… | |
| Analizada | Media (5.3) | 0.54% | — | Rems Profile Registration Without Reload/refresh | 23/9/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0. This affects an unknown part of the file del.php of the component GET Parameter Handler. The manipulation of the argument list leads to sql injection. It is possible to initiate the attack remotely.… | |
| Analizada | Media (5.3) | 0.46% | — | Rems Profile Registration Without Reload/refresh | 23/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add.php of the component Registration Form. The manipulation of the argument full_name leads to cross site scripting. The… | |
| Analizada | Media (5.4) | 0.30% | — | Wp-brandtheme Preloader Plus | 7/9/2024 | 17/6/2026 | The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Media (4.3) | 0.40% | — | Comment Images ReloadedAI | 9/7/2024 | 17/6/2026 | The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Media (5.3) | 0.51% | — | Webtoffee Preloader FOR WebsiteAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2. | |
| Modificada | Alta (7.5) | 0.51% | — | Wpkube Subscribe TO Comments Reloaded | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725. | |
| Aplazada | Alta (7.1) | 0.23% | — | Sverde1 Watermark ReloadedAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sverde1 Watermark RELOADED watermark-reloaded allows Cross Site Request Forgery.This issue affects Watermark RELOADED: from n/a through <= 1.3.5. | |
| Analizada | Crítica (9.8) | 0.69% | — | Remyandrade Crud Without Page Reload/refresh | 12/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add_user.php. The manipulation of the argument city leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.57% | — | Remyandrade Crud Without Page Reload/refresh | 3/2/2024 | 17/6/2026 | A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file fetch_data.php. The manipulation of the argument username/city leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.43% | — | Limitloginattempts Limit Login Attempts Reloaded | 11/1/2024 | 17/6/2026 | The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.3) | 0.45% | — | Limitloginattempts Limit Login Attempts Reloaded | 27/11/2023 | 17/6/2026 | The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin. | |
| Modificada | Alta (8.8) | 0.29% | — | Nkb-bd Preloader Matrix | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lukman Nakib Preloader Matrix.This issue affects Preloader Matrix: from n/a through 2.0.1. | |
| Modificada | Alta (7.8) | 0.20% | — | Lenovo Preload Directory | 8/11/2023 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges. | |
| Modificada | Alta (8.8) | 0.21% | — | Thefreewindows Auto Limit Posts Reloaded | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TheFreeWindows Auto Limit Posts Reloaded plugin <= 2.5 versions. | |
| Modificada | Media (5.4) | 0.46% | — | Wpexperts User Avatar-reloaded | 16/10/2023 | 17/6/2026 | The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks. | |
| Modificada | Media (6.1) | 1.0% | — | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (4.8) | 0.39% | — | Catchsquare WP Smart Preloader | 30/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catchsquare WP Smart Preloader plugin <= 1.15 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Wp-table Reloaded Project Wp-table Reloaded | 9/1/2023 | 17/6/2026 | The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such… | |
| Modificada | Media (6.5) | 0.52% | — | Jenkins Matrix Reloaded | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Matrix Reloaded | 30/6/2022 | 17/6/2026 | Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | |
| Modificada | Media (5.4) | 0.39% | — | Wpkube Subscribe TO Comments Reloaded | 29/4/2022 | 17/6/2026 | Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications… | |
| Modificada | Crítica (9.6) | 2.2% | — | PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial Project PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial | 24/1/2022 | 17/6/2026 | Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud. | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. |