Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.28%—Nuggethon Custom Order Status Manager FOR Woocommerce29/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2.
ModificadaMedia (6.1)0.41%—Ifeelweb Post Status Notifier Lite22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post Status Notifier Lite plugin <= 1.11.0 versions.
ModificadaMedia (5.7)0.25%—Status Powerbpm2/6/202317/6/2026
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
ModificadaMedia (6.5)0.34%—Woocommerce Order Status Change Notifier15/5/202317/6/2026
The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without…
ModificadaMedia (5.5)0.23%—Jenkins Github Pull Request Coverage Status26/1/202317/6/2026
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (6.1)0.90%—Ifeelweb Post Status Notifier Lite9/1/202317/6/2026
The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.
ModificadaAlta (7.8)0.45%—Powerline Gitstatus Project Powerline GitstatusDebian Linux13/10/202217/6/2026
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus, changing to a directory automatically runs git commands in order…
ModificadaMedia (6.1)0.90%—Scratchstatus Scratchtools27/6/202217/6/2026
ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching) easier. In affected versions anybody who uses the Recently Viewed Projects feature is vulnerable to having their account taken over if they view a project that tries to. The issue is that if a user…
ModificadaAlta (7.5)1.2%—Jenkins Embeddable Build Status23/6/202217/6/2026
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
ModificadaAlta (7.5)1.7%—Jenkins Embeddable Build Status23/6/202217/6/2026
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to…
ModificadaMedia (6.1)0.96%—Jenkins Embeddable Build Status23/6/202217/6/2026
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.
ModificadaMedia (5.4)0.59%—Aptis-solutions Server Status7/6/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Server Status. This issue affects some unknown processing of the component HTTP Status/SMTP Status. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaAlta (8.8)1.3%—NI Woocommerce Custom Order Status Project NI Woocommerce Custom Order Status21/12/202117/6/2026
The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated…
ModificadaAlta (7.2)1.3%—Game-server-status Project Game-server-status25/10/202117/6/2026
The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenticated SQL Injection in an admin page
ModificadaMedia (5.4)0.62%—Status301 Coolclock27/9/202117/6/2026
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.77%—Activefusions Order Status Batch Change17/9/202117/6/2026
Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (5.4)0.68%—3.7designs Project Status23/8/202117/6/2026
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue
ModificadaMedia (5.4)0.94%—Obss Time IN Status8/3/202117/6/2026
In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaCrítica (9.8)15%—Status2k7/2/202017/6/2026
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
ModificadaMedia (5.3)0.85%—Statusnet7/2/202016/6/2026
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
ModificadaCrítica (9.8)3.8%—Status2k10/1/202017/6/2026
Status2k does not remove the install directory allowing credential reset.
ModificadaAlta (8.8)7.1%—Status2k10/1/202017/6/2026
Status2k allows Remote Command Execution in admin/options/editpl.php.
ModificadaMedia (6.1)0.92%—Statusnet20/11/201916/6/2026
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
ModificadaCrítica (9.8)1.3%—Statusnet20/11/201916/6/2026
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..