Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.33% | — | Coderevolution Echo RSS Feed Post GeneratorAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution Echo RSS Feed Post Generator Plugin for WordPress rss-feed-post-generator-echo allows Reflected XSS.This issue affects Echo RSS Feed Post Generator Plugin for WordPress: from n/a through <= 5.4.8.1. | |
| Aplazada | Alta (7.5) | 0.68% | — | Magentech RevoAI | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Revo revo allows PHP Local File Inclusion.This issue affects Revo: from n/a through <= 4.0.26. | |
| Aplazada | Alta (7.1) | 0.28% | — | Lambertgroup Revolution Video PlayerAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Revolution Video Player revolution_video_player allows Reflected XSS.This issue affects Revolution Video Player: from n/a through <= 2.9.2. | |
| Aplazada | Media (5.3) | 0.36% | — | Coderevolution Crawlomatic Multisite Scraper Post GeneratorAI | 6/6/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage-scraper-post-generator allows Retrieve Embedded Sensitive Data.This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through <= 2.6.8.2. | |
| Aplazada | Media (4.3) | 0.28% | — | Coderevolution Crawlomatic Multisite Scraper Post GeneratorAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage-scraper-post-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through <= 2.6.8.2. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Coderevolution Echo RSS Feed Post GeneratorAI | 17/5/2025 | 17/6/2026 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Alta (7.3) | 0.20% | — | Mechrevo Control ConsoleAI | 5/5/2025 | 17/6/2026 | A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService. The manipulation leads to uncontrolled… | |
| Aplazada | Crítica (9.3) | 0.77% | — | Kunbus Revolution PI OSAINodered Node-redAI | 1/5/2025 | 17/6/2026 | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system. | |
| Aplazada | Alta (7.1) | 0.15% | — | Steveorevo Domain ThemeAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a through <= 1.3. | |
| Analizada | Alta (8.8) | 0.76% | — | Coderevolution Aiomatic | 8/3/2025 | 17/6/2026 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_generate_featured_image' function in all versions up to, and including, 2.3.8. This makes it possible for… | |
| Analizada | Media (5.4) | 0.24% | — | Coderevolution Aiomatic | 8/3/2025 | 17/6/2026 | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. This makes it possible for… | |
| Aplazada | Baja (2.7) | 0.21% | — | Revoworks ScvxAIRevoworks BrowserAI | 26/2/2025 | 17/6/2026 | Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product. | |
| Aplazada | Media (4.3) | 0.48% | — | Kunbus Gmbh Revolution PIAI | 10/2/2025 | 17/6/2026 | Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter. | |
| Aplazada | Alta (8.3) | 1.2% | — | Kunbus Revolution PIAI | 10/2/2025 | 17/6/2026 | OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to execute OS commands on the device via the ‘php/dal.php’ endpoint, in the ‘arrSaveConfig’ parameter. | |
| Modificada | Media (5.4) | 0.26% | — | Coderevolution WP Pocket Urls | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs wp-pocket-urls allows Stored XSS.This issue affects WP Pocket URLs: from n/a through <= 1.0.3. | |
| Analizada | Media (4.3) | 0.18% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 10/10/2024 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthenticated… | |
| Analizada | Crítica (9.8) | 0.62% | — | Coderevolution Echo RSS Feed Post Generator | 1/10/2024 | 17/6/2026 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for… | |
| Analizada | Media (5.4) | 0.32% | — | Themepunch Slider Revolution | 1/10/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Alta (7.8) | 0.17% | — | Revoworks Cloud ClientAI | 1/10/2024 | 17/6/2026 | RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However,… | |
| Analizada | Media (5.3) | 0.33% | — | Revolut Gateway FOR Woocommerce | 25/9/2024 | 17/6/2026 | The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions up to, and including, 4.17.3. This makes it possible for unauthenticated attackers to mark orders as completed. | |
| Analizada | Media (5.3) | 0.35% | — | Coderevolution Aiomatic | 27/7/2024 | 17/6/2026 | The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it… | |
| Modificada | Media (4.8) | 0.26% | — | Themepunch Slider Revolution | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13. | |
| Analizada | Media (6.9) | 0.41% | — | Adminerevo | 24/6/2024 | 17/6/2026 | Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4. | |
| Analizada | Media (6.9) | 0.58% | — | Adminerevo | 24/6/2024 | 17/6/2026 | Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version… | |
| Modificada | Crítica (9.2) | 0.66% | — | Adminerevo | 21/6/2024 | 17/6/2026 | The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3. |