Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.16% | — | Dictionary Wordpress Plugin DictionaryAI | 17/9/2026 | 18/9/2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Aplazada | Media (5.3) | 0.27% | — | LoginwordpressAIWwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out… | |
| Aplazada | Alta (7.1) | 0.34% | — | Multivendorx Wordpress PluginAI | 16/9/2026 | 17/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and payout settings and to replace the record of who owns it. | |
| Aplazada | Media (6.1) | 0.23% | — | Wordplus Better MessagesAI | 16/9/2026 | 18/9/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.7) | 0.54% | — | Wordpress Design Scuole ItaliaAI | 15/9/2026 | 18/9/2026 | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process. | |
| Aplazada | Alta (8.8) | 0.50% | — | GeniewordsAI | 13/9/2026 | 14/9/2026 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page. | |
| Aplazada | Media (5.5) | 0.32% | — | Storeapps Temporary Login Without PasswordAI | 12/9/2026 | 14/9/2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC… | |
| Aplazada | Alta (7.2) | 0.46% | — | Storeapps Temporary Login Without PasswordAI | 12/9/2026 | 14/9/2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing… | |
| Aplazada | Alta (7.2) | 0.46% | — | Multivendorx Wordpress PluginAI | 11/9/2026 | 11/9/2026 | The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. | |
| Aplazada | Baja (3.5) | 0.14% | — | Translate Wordpress With GtranslateAI | 11/9/2026 | 11/9/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. | |
| Aplazada | Alta (8) | 0.23% | — | Bulk Password ResetAI | 10/9/2026 | 10/9/2026 | The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a… | |
| Aplazada | Alta (8.7) | 0.37% | — | PasswordpusherAI | 9/9/2026 | 10/9/2026 | PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show endpoint to access one-time secrets multiple times before the view count is… | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 8/9/2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 8/9/2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 8/9/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 8/9/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |