Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.19% | — | Alobaidi Extend LinkAI | 19/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.4) | 0.24% | — | Advance Block ExtendAI | 19/2/2026 | 17/6/2026 | The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attribute in the Latest Posts Gutenberg block in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.28% | — | Extendthemes Mesmerize CompanionAIExtendthemes MesmerizeAI | 19/2/2026 | 17/6/2026 | The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the "openPageInCustomizer" and "openPageInDefaultEditor" functions in all versions up to, and including, 1.6.158. This makes it possible for authenticated attackers - with… | |
| Aplazada | Media (4.4) | 0.28% | — | Extended Random Number GeneratorAI | 4/2/2026 | 17/6/2026 | The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Aplazada | Crítica (9.5) | 1.5% | — | Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+2 | 30/1/2026 | 17/6/2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects | |
| Aplazada | Crítica (9.8) | 1.5% | — | Acfextended Advanced Custom Fields ExtendedAI | 20/1/2026 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Alta (7.1) | 0.22% | — | Xtendify WofficeAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30. | |
| Aplazada | Media (5.4) | 0.19% | — | Extendons WP ScraperAI | 31/12/2025 | 23/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through <= 1.0.7. | |
| Modificada | Alta (8.8) | 0.21% | — | Extendthemes Vireo | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24. | |
| Aplazada | Media (6.4) | 0.29% | — | Extendthemes Colibri Page BuilderAI | 19/12/2025 | 17/6/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.22% | — | Extendthemes Colibri Page BuilderAI | 13/12/2025 | 7/10/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_loop' shortcode in all versions up to, and including, 1.0.335 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (7.2) | 1.7% | — | Fortinet Fortiextender Firmware | 9/12/2025 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via… | |
| Aplazada | Media (6.5) | 0.19% | — | GET Bowtied Shopkeeper ExtenderAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0. | |
| Aplazada | Crítica (9.8) | 68% | 💥 Exploit | Acfextended Advanced Custom Fields ExtendedAI | 3/12/2025 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.15% | — | Nextend Social Login AND RegisterAI | 28/11/2025 | 30/9/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This makes it possible for unauthenticated attackers to unlink the user's social login… | |
| Modificada | Alta (7.8) | 0.15% | — | Fortinet Fortiextender Firmware | 18/11/2025 | 17/6/2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI… | |
| Analizada | Media (5.5) | 0.16% | — | Fortinet Fortiextender Firmware | 18/11/2025 | 17/6/2026 | A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands. | |
| Aplazada | Media (5.5) | 0.20% | — | Wpseek Admin Management XtendedAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin Management Xtended : from n/a through <= 2.5.1. | |
| Aplazada | Alta (8.8) | 0.39% | — | Extendons Woocommerce Registration FieldsAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Privilege Escalation.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a through <= 3.2.3. | |
| Modificada | Media (5.9) | 0.22% | — | Extendthemes Colibri Page Builder | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder colibri-page-builder allows Stored XSS.This issue affects Colibri Page Builder: from n/a through < 1.0.334. | |
| Aplazada | Alta (7.1) | 0.28% | — | Extendons Woocommerce Registration Fields PluginAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Reflected XSS.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a… | |
| Aplazada | Media (6.4) | 0.23% | — | Extendthemes Colibri Page BuilderAI | 11/10/2025 | 17/6/2026 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 0.68% | — | IBM Transformation Extender Advanced | 6/10/2025 | 17/6/2026 | IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Analizada | Media (6.2) | 0.11% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls. | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. |