Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.36%—Fetchdesigns Sign-up SheetsAI1/11/202417/6/2026
Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12.
AnalizadaMedia (6.1)0.39%—Fetchdesigns Sign-up Sheets4/9/202417/6/2026
The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.
AplazadaCrítica (9.1)0.49%—Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI12/7/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.
ModificadaMedia (6.5)0.35%—Gsheetconnector CF7 Google Sheets Connector8/6/202417/6/2026
The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'execute_post_data_cg7_free' function in all versions up to, and including, 5.0.9. This makes it possible for unauthenticated attackers to toggle site configuration settings,…
AplazadaMedia (5.9)0.36%—Wppool Sheets TO WP Table Live SyncAI6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0.
AplazadaMedia (4.3)0.20%—Fetchdesigns Sign-up SheetsAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1.
AplazadaAlta (7.5)0.52%—Gsheetconnector CF7 Google Sheets ConnectorAI26/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5.
ModificadaMedia (5.4)0.38%—Spreadsheetconverter Import Spreadsheets30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Stored XSS.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.3.
ModificadaAlta (8.8)0.30%—Wppool Sheets TO WP Table Live Sync22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.
ModificadaAlta (7.5)0.39%—Grafana Google Sheets16/10/202317/6/2026
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is…
ModificadaAlta (8.8)0.25%—Fetchdesigns Sign-up Sheets3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions.
ModificadaAlta (8.8)0.39%—Gsheetconnector Caldera Forms Google Sheets Connector17/7/202317/6/2026
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
ModificadaMedia (6.1)0.46%—Gsheetconnector CF7 Google Sheets Connector4/7/202317/6/2026
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.5)0.31%—Gsheetconnector Gravity Forms Google Sheets Connector27/6/202317/6/2026
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
ModificadaMedia (5.4)0.44%—Timesheets-for-jira Timesheet Tracking17/4/202317/6/2026
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
ModificadaMedia (4.8)0.44%—Dcac Time Sheets10/4/202317/6/2026
The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8)1.3%—Fetchdesigns Sign-up Sheets12/7/202117/6/2026
The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue
ModificadaMedia (4.8)0.62%—Fetchdesigns Sign-up Sheets12/7/202117/6/2026
The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard
ModificadaMedia (6.1)0.91%—Time Sheets Project Time Sheets22/8/201917/6/2026
The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.91%—Time Sheets Project Time Sheets22/8/201917/6/2026
The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
ModificadaAlta (9.3)4.2%—Kingsoft Spreadsheets 201229/7/201316/6/2026
Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a crafted spreadsheet file.
ModificadaMedia (5)2.8%—Riceball Multiple Time Sheets20/3/200816/6/2026
Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter.
ModificadaMedia (4.3)1.8%—Riceball Multiple Time Sheets20/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4)…
ModificadaMedia (4.6)0.41%—Redhat Docbook StylesheetsRedhat Docbook Utils29/5/200216/6/2026
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.