Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.60% | 💥 PoC | Opensearch Dashboards-reportingAIOpensearchAI | 12/2/2025 | 17/6/2026 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer. | |
| Analizada | Media (5.4) | 0.30% | — | Wpo-hr NGG Smart Image Search | 12/2/2025 | 17/6/2026 | The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.9) | 0.39% | — | Dreamvention Live Ajax Search FreeAIOpencartAI | 8/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart. Affected by this issue is the function searchresults/search of the file /?route=extension/live_search/module/live_search.searchresults. The manipulation of the argument keyword leads to sql… | |
| Aplazada | Media (6.5) | 0.28% | — | MAX Chirkov Flexidx Home SearchAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Chirkov FlexIDX Home Search flexidx-home-search allows Stored XSS.This issue affects FlexIDX Home Search: from n/a through <= 2.1.2. | |
| Analizada | Media (5.4) | 0.25% | — | Sitesearch360 Site Search 360 | 1/2/2025 | 17/6/2026 | The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultblock' shortcode in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.32% | — | SAV WP OpensearchAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sav WP OpenSearch wp-opensearch allows Stored XSS.This issue affects WP OpenSearch: from n/a through <= 1.0. | |
| Analizada | Media (6.1) | 0.59% | 💥 Exploit | Parisholley Fantastic Elasticsearch | 31/1/2025 | 17/6/2026 | The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.5) | 0.51% | — | Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI | 30/1/2025 | 17/6/2026 | In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack. | |
| Aplazada | Media (6.5) | 0.32% | — | Guangzhou Polar Future Culture Technology University SearchAI | 27/1/2025 | 17/6/2026 | An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.26% | — | Epsiloncool WP Fast Total SearchAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affects WP Fast Total Search: from n/a through <= 1.78.258. | |
| Aplazada | Media (5.4) | 0.46% | — | Epsiloncool WP Fast Total SearchAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Fast Total Search: from n/a through <= 1.78.258. | |
| Aplazada | Alta (7.1) | 0.30% | — | Markcoker Wordpress File SearchAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markcoker WordPress File Search wpfilesearch allows Reflected XSS.This issue affects WordPress File Search: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Kinlane Ctygrid Hyp3rl0cal SearchAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kinlane CtyGrid Hyp3rL0cal Search hyp3rl0cal-city-search allows Reflected XSS.This issue affects CtyGrid Hyp3rL0cal Search: from n/a through <= 0.1.1.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Chetan Khandla Woocommerce Order SearchAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chetan Khandla WooCommerce Order Search woocommerce-order-searching allows Reflected XSS.This issue affects WooCommerce Order Search: from n/a through <= 1.1.0. | |
| Modificada | Alta (7.5) | 0.62% | — | Elasticsearch | 21/1/2025 | 17/6/2026 | An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function. | |
| Aplazada | Media (6.5) | 0.23% | — | Tc.k Ajax WP Query Search FilterAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Ajax WP Query Search Filter ajax-wp-query-search-filter allows Stored XSS.This issue affects Ajax WP Query Search Filter: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.1) | 0.17% | — | Ivanra10 WP Custom Google SearchAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ivanra10 WP Custom Google Search wp-custom-google-search allows Stored XSS.This issue affects WP Custom Google Search: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Damniel Lijit Search Wp-lijit-wijitAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in damniel Lijit Search wp-lijit-wijit allows Reflected XSS.This issue affects Lijit Search: from n/a through <= 1.1. | |
| Aplazada | Media (6.4) | 0.33% | — | SearchieAI | 9/1/2025 | 17/6/2026 | The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7) | 0.40% | — | RedisearchAI | 8/1/2025 | 17/6/2026 | RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT command argument, or FT.SEARCH with a specially crafted KNN command argument, can trigger an integer overflow, leading… | |
| Aplazada | Media (4.3) | 0.17% | — | Epsiloncool WP Fast Total SearchAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.69.234. | |
| Modificada | Media (4.3) | 0.17% | — | Searchiq | 31/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a through <= 4.6. | |
| Analizada | Media (6) | 0.46% | — | Elasticsearch | 17/12/2024 | 17/6/2026 | An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow. | |
| Aplazada | Media (6.4) | 0.37% | — | MY IDX Home SearchAI | 14/12/2024 | 17/6/2026 | The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-landing' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | MY IDX Home SearchAI | 14/12/2024 | 17/6/2026 | The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-search' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |