Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Bedevious Password Reset With Code FOR Wordpress Rest API7/12/202317/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.
ModificadaMedia (5.4)0.28%—Minapper Rest API TO Miniprogram16/8/202317/6/2026
The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
ModificadaMedia (5.9)0.35%—Icepay Rest API12/3/202317/6/2026
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper validation of integrity check value. The attack can be launched…
ModificadaAlta (8.8)0.29%—Miniorange Wordpress Rest API Authentication18/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
ModificadaMedia (4.8)0.60%—Commonninja Easily Generate Rest API9/5/202217/6/2026
The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.5)3.3%—Codingforentrepreneurs Opencv Rest API12/11/202117/6/2026
OpenCV-REST-API master branch as of commit 69be158c05d4dd5a4aff38fdc680a162dd6b9e49 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.
ModificadaCrítica (9.9)2.9%—Zstack Rest API17/8/202117/6/2026
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication Remote Code Execution (RCE) via bypass of the Groovy shell sandbox. The REST…
ModificadaAlta (7.5)1.1%—Synopsys Hub-rest-api-python6/11/202017/6/2026
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
ModificadaAlta (7.5)13%—ACF TO Rest API Project ACF TO Rest API24/6/202017/6/2026
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.
ModificadaAlta (10)1.2%—Andrew Sterling Hanenkamp Rest API Module24/9/200916/6/2026
Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors.