Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.33% | — | Membership PluginAI | 18/2/2026 | 17/6/2026 | The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice settings fields in all versions up to, and including, 3.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (7.5) | 0.54% | 💥 PoC | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Alta (8.8) | 0.75% | — | Weplugins WP MapsAI | 17/2/2026 | 17/6/2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (5.8) | 0.10% | — | Genetec Sipelia PluginAI | 13/2/2026 | 17/6/2026 | Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system. | |
| Aplazada | Alta (7.5) | 0.34% | — | Monkeybread Software MBS Dynapdf PluginAI | 12/2/2026 | 17/6/2026 | A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (8.8) | 0.34% | — | Videospirecore Theme PluginAI | 11/2/2026 | 17/6/2026 | The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.6. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated… | |
| Analizada | Alta (7.7) | 0.22% | — | SAP Solution Tools Plug-in | 10/2/2026 | 17/6/2026 | SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability. | |
| Analizada | Media (4.3) | 0.18% | — | SAP Solution Tools Plug-in | 10/2/2026 | 17/6/2026 | Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This… | |
| Analizada | Media (4.3) | 0.18% | — | SAP Solution Tools Plug-in | 10/2/2026 | 17/6/2026 | In ABAP based SAP systems a remote enabled function module does not perform necessary authorization checks for an authenticated user resulting in disclosure of system information.This has low impact on confidentiality. Integrity and availability are not impacted. | |
| Aplazada | Crítica (9.3) | 0.73% | — | Craftcms Vcard PluginAI | 3/2/2026 | 17/6/2026 | CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a… | |
| Aplazada | Media (5.4) | 0.11% | — | Simple-membership-plugin Simple Membership WP User ImportAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1. | |
| Aplazada | Media (4.3) | 0.15% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/2/2026 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks. | |
| Aplazada | Media (4.4) | 0.22% | — | WP Google AD Manager PluginAI | 28/1/2026 | 17/6/2026 | The WP Google Ad Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Aplazada | Media (4.3) | 0.22% | — | Bplugins Document EmbedderAI | 28/1/2026 | 17/6/2026 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.4. This is due to the plugin not verifying that a user has permission to access the requested resource in the 'bplde_save_document_library',… | |
| Aplazada | Media (5.1) | 0.29% | — | Igniterealtime OpenfireAIOpenfire Nodejs PluginAI | 26/1/2026 | 17/6/2026 | Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration… | |
| Aplazada | Media (5.1) | 0.64% | — | Getgrav GravAIGetgrav Admin PluginAI | 26/1/2026 | 17/6/2026 | Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the… | |
| Aplazada | Media (5.9) | 0.20% | — | Pluginops Landing Page BuilderAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue affects Landing Page Builder: from n/a through <= 1.5.3.4. | |
| Aplazada | Media (5.3) | 0.35% | — | Xlplugins Nextmove LiteAI | 23/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0. | |
| Aplazada | Media (6.5) | 0.32% | — | Bplugins B AccordionAI | 23/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in bPlugins B Accordion b-accordion allows Retrieve Embedded Sensitive Data.This issue affects B Accordion: from n/a through <= 2.0.2. | |
| Aplazada | Media (6.5) | 0.15% | — | Bplugins B SliderAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider b-slider allows DOM-Based XSS.This issue affects B Slider: from n/a through <= 2.0.6. | |
| Aplazada | Alta (7.6) | 0.32% | — | Firestormplugins Firestorm Professional Real EstateAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real Estate fs-real-estate-plugin allows Blind SQL Injection.This issue affects FireStorm Professional Real Estate: from n/a through <= 2.7.11. | |
| Aplazada | Media (4.3) | 0.21% | — | Absoluteplugins Absolute Addons FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Absolute Addons For Elementor: from n/a through <= 1.0.14. | |
| Aplazada | Alta (7.1) | 0.21% | — | Hmplugin JobwpAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hossni Mubarak JobWP jobwp allows Stored XSS.This issue affects JobWP: from n/a through <= 2.4.5. | |
| Aplazada | Alta (8.8) | 0.32% | — | E-plugins Final UserAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a through <= 1.2.5. | |
| Aplazada | Alta (8.8) | 0.32% | — | E-plugins WP MembershipAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4. |