Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.38% | — | Wpchill Simple RestrictAI | 10/12/2024 | 17/6/2026 | The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as… | |
| Modificada | Crítica (9.8) | 0.49% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in NicheAddons Restaurant & Cafe Addon for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through 1.5.3. | |
| Modificada | Media (5.3) | 0.41% | — | Wpeverest User Registration | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1. | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Aplazada | Media (5.3) | 0.30% | — | Restapp INC Online Ordering SystemAI | 4/12/2024 | 17/6/2026 | Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online Ordering System allows Integer Attacks. This issue affects Online Ordering System: 8.2.1. NOTE: Vulnerability fixed in version 8.2.2 and does not exist before 8.2.1. | |
| Analizada | Media (5.4) | 0.29% | — | Gsplugins GS Pinterest Portfolio | 3/12/2024 | 17/6/2026 | The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.5) | 0.29% | — | Socialevolution WP Find Your NearestAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Stored XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Analizada | Media (5.3) | 0.66% | — | Prestashop | 29/11/2024 | 17/6/2026 | In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. | |
| Analizada | Media (4.3) | 0.39% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 28/11/2024 | 17/6/2026 | The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.8) | 0.38% | — | Wpeverest Everest Forms | 26/11/2024 | 17/6/2026 | The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.4) | 0.38% | — | Gladinet CentrestackAI | 22/11/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Gladinet CentrestackAI | 22/11/2024 | 17/6/2026 | An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field. | |
| Analizada | Media (5.3) | 0.57% | — | Cayenne Anonymous Restricted Content | 21/11/2024 | 17/6/2026 | The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to logged-in users. | |
| Aplazada | Media (6.4) | 0.53% | — | Prestalife Product DesignerAI | 21/11/2024 | 17/6/2026 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Media (6.1) | 0.32% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 20/11/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (7.8) | 7.9% | — | Needrestart Project Needrestart | 19/11/2024 | 17/6/2026 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable. | |
| Modificada | Alta (7.8) | 6.0% | — | Needrestart Project Needrestart | 19/11/2024 | 17/6/2026 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a… | |
| Modificada | Alta (7.8) | 21% | 💥 Exploit | Needrestart Project Needrestart | 19/11/2024 | 17/6/2026 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable. | |
| Modificada | Alta (7.8) | 12% | 💥 PoC | Needrestart Project Needrestart | 19/11/2024 | 17/6/2026 | Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps. | |
| Aplazada | Media (6.5) | 0.39% | — | Marco Piarulli MY Restaurant MenuAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Piarulli My Restaurant Menu my-restaurant-menu allows Stored XSS.This issue affects My Restaurant Menu: from n/a through <= 0.2.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Wordpresteem WE Client Logo CarouselAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordpresteem WE – Client Logo Carousel we-client-logo-carousel allows Stored XSS.This issue affects WE – Client Logo Carousel: from n/a through <= 1.4. | |
| Aplazada | Media (6.5) | 0.39% | — | Shahjahan Jewel Trendy Restaurant MenuAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjahan Jewel Trendy Restaurant Menu trendy-restaurant-menu allows DOM-Based XSS.This issue affects Trendy Restaurant Menu: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.35% | — | Auburnforest DatamentorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AuburnForest DataMentor datamentor allows DOM-Based XSS.This issue affects DataMentor: from n/a through <= 1.7. | |
| Modificada | Media (5.4) | 0.26% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 10/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows Stored XSS.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through <= 1.5.6. | |
| Analizada | Alta (7.3) | 0.46% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 9/11/2024 | 17/6/2026 | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a… |