Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.36% | — | Fetchdesigns Sign-up SheetsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12. | |
| Analizada | Media (6.1) | 0.39% | — | Fetchdesigns Sign-up Sheets | 4/9/2024 | 17/6/2026 | The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI | 12/7/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4. | |
| Modificada | Media (6.5) | 0.35% | — | Gsheetconnector CF7 Google Sheets Connector | 8/6/2024 | 17/6/2026 | The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'execute_post_data_cg7_free' function in all versions up to, and including, 5.0.9. This makes it possible for unauthenticated attackers to toggle site configuration settings,… | |
| Aplazada | Media (5.9) | 0.36% | — | Wppool Sheets TO WP Table Live SyncAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0. | |
| Aplazada | Media (4.3) | 0.20% | — | Fetchdesigns Sign-up SheetsAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1. | |
| Aplazada | Alta (7.5) | 0.52% | — | Gsheetconnector CF7 Google Sheets ConnectorAI | 26/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5. | |
| Modificada | Media (5.4) | 0.38% | — | Spreadsheetconverter Import Spreadsheets | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Stored XSS.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.3. | |
| Modificada | Alta (8.8) | 0.30% | — | Wppool Sheets TO WP Table Live Sync | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions. | |
| Modificada | Alta (7.5) | 0.39% | — | Grafana Google Sheets | 16/10/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is… | |
| Modificada | Alta (8.8) | 0.25% | — | Fetchdesigns Sign-up Sheets | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions. | |
| Modificada | Alta (8.8) | 0.39% | — | Gsheetconnector Caldera Forms Google Sheets Connector | 17/7/2023 | 17/6/2026 | The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (6.1) | 0.46% | — | Gsheetconnector CF7 Google Sheets Connector | 4/7/2023 | 17/6/2026 | The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.5) | 0.31% | — | Gsheetconnector Gravity Forms Google Sheets Connector | 27/6/2023 | 17/6/2026 | The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (5.4) | 0.44% | — | Timesheets-for-jira Timesheet Tracking | 17/4/2023 | 17/6/2026 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. | |
| Modificada | Media (4.8) | 0.44% | — | Dcac Time Sheets | 10/4/2023 | 17/6/2026 | The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8) | 1.3% | — | Fetchdesigns Sign-up Sheets | 12/7/2021 | 17/6/2026 | The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue | |
| Modificada | Media (4.8) | 0.62% | — | Fetchdesigns Sign-up Sheets | 12/7/2021 | 17/6/2026 | The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard | |
| Modificada | Media (6.1) | 0.91% | — | Time Sheets Project Time Sheets | 22/8/2019 | 17/6/2026 | The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.91% | — | Time Sheets Project Time Sheets | 22/8/2019 | 17/6/2026 | The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list. | |
| Modificada | Alta (9.3) | 4.2% | — | Kingsoft Spreadsheets 2012 | 29/7/2013 | 16/6/2026 | Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a crafted spreadsheet file. | |
| Modificada | Media (5) | 2.8% | — | Riceball Multiple Time Sheets | 20/3/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Riceball Multiple Time Sheets | 20/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4)… | |
| Modificada | Media (4.6) | 0.41% | — | Redhat Docbook StylesheetsRedhat Docbook Utils | 29/5/2002 | 16/6/2026 | The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier. |