Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.28% | — | Nuggethon Custom Order Status Manager FOR Woocommerce | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2. | |
| Modificada | Media (6.1) | 0.41% | — | Ifeelweb Post Status Notifier Lite | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post Status Notifier Lite plugin <= 1.11.0 versions. | |
| Modificada | Media (5.7) | 0.25% | — | Status Powerbpm | 2/6/2023 | 17/6/2026 | It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence. | |
| Modificada | Media (6.5) | 0.34% | — | Woocommerce Order Status Change Notifier | 15/5/2023 | 17/6/2026 | The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without… | |
| Modificada | Media (5.5) | 0.23% | — | Jenkins Github Pull Request Coverage Status | 26/1/2023 | 17/6/2026 | Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.1) | 0.90% | — | Ifeelweb Post Status Notifier Lite | 9/1/2023 | 17/6/2026 | The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin. | |
| Modificada | Alta (7.8) | 0.45% | — | Powerline Gitstatus Project Powerline GitstatusDebian Linux | 13/10/2022 | 17/6/2026 | powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus, changing to a directory automatically runs git commands in order… | |
| Modificada | Media (6.1) | 0.90% | — | Scratchstatus Scratchtools | 27/6/2022 | 17/6/2026 | ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching) easier. In affected versions anybody who uses the Recently Viewed Projects feature is vulnerable to having their account taken over if they view a project that tries to. The issue is that if a user… | |
| Modificada | Alta (7.5) | 1.2% | — | Jenkins Embeddable Build Status | 23/6/2022 | 17/6/2026 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build. | |
| Modificada | Alta (7.5) | 1.7% | — | Jenkins Embeddable Build Status | 23/6/2022 | 17/6/2026 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to… | |
| Modificada | Media (6.1) | 0.96% | — | Jenkins Embeddable Build Status | 23/6/2022 | 17/6/2026 | Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (5.4) | 0.59% | — | Aptis-solutions Server Status | 7/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Server Status. This issue affects some unknown processing of the component HTTP Status/SMTP Status. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Alta (8.8) | 1.3% | — | NI Woocommerce Custom Order Status Project NI Woocommerce Custom Order Status | 21/12/2021 | 17/6/2026 | The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated… | |
| Modificada | Alta (7.2) | 1.3% | — | Game-server-status Project Game-server-status | 25/10/2021 | 17/6/2026 | The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenticated SQL Injection in an admin page | |
| Modificada | Media (5.4) | 0.62% | — | Status301 Coolclock | 27/9/2021 | 17/6/2026 | The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.77% | — | Activefusions Order Status Batch Change | 17/9/2021 | 17/6/2026 | Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.68% | — | 3.7designs Project Status | 23/8/2021 | 17/6/2026 | The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue | |
| Modificada | Media (5.4) | 0.94% | — | Obss Time IN Status | 8/3/2021 | 17/6/2026 | In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.8) | 15% | — | Status2k | 7/2/2020 | 17/6/2026 | A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code. | |
| Modificada | Media (5.3) | 0.85% | — | Statusnet | 7/2/2020 | 16/6/2026 | statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks. | |
| Modificada | Crítica (9.8) | 3.8% | — | Status2k | 10/1/2020 | 17/6/2026 | Status2k does not remove the install directory allowing credential reset. | |
| Modificada | Alta (8.8) | 7.1% | — | Status2k | 10/1/2020 | 17/6/2026 | Status2k allows Remote Command Execution in admin/options/editpl.php. | |
| Modificada | Media (6.1) | 0.92% | — | Statusnet | 20/11/2019 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents. | |
| Modificada | Crítica (9.8) | 1.3% | — | Statusnet | 20/11/2019 | 16/6/2026 | Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. |