Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins WP MembershipAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Membership: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Real Estate PROAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Real Estate Pro real-estate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Pro: from n/a through <= 2.1.5. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins ListinghubAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins ListingHub listinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingHub: from n/a through <= 1.2.7. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins ListihubAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Listihub listihub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Listihub: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Fitness-trainerAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins fitness-trainer fitness-trainer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects fitness-trainer: from n/a through <= 1.7.1. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Final UserAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Final User final-user allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Final User: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Hospital Doctor DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Institutions-directoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3.4. | |
| Aplazada | Alta (8.8) | 0.44% | — | E-plugins Hospital Doctor DirectoryAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Privilege Escalation.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9. | |
| Aplazada | Alta (8.8) | 0.44% | — | E-plugins Institutions DirectoryAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege Escalation.This issue affects Institutions Directory: from n/a through <= 1.3.4. | |
| Aplazada | Alta (7.3) | 0.34% | — | E-plugins Lawyer DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Directory: from n/a through <= 1.3.4. | |
| Aplazada | Media (6.5) | 0.28% | — | Designthemes Dt-reservation-pluginAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reservation Plugin: from n/a through <= 1.7. | |
| Aplazada | Alta (7.1) | 0.21% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Hotel ListingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hotel Listing hotel-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Listing: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.6) | 0.32% | — | E-plugins Institutions DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3..4. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Hospital Doctor DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9. | |
| Aplazada | Media (6.5) | 0.40% | — | Cleverplugins SEO BoosterAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in cleverplugins SEO Booster seo-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Booster: from n/a through <= 6.1.8. | |
| Aplazada | Crítica (9.4) | 0.36% | — | Pluginbazaar Order Listener FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Lawyer DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Directory: from n/a through <= 1.3.3. | |
| Aplazada | Alta (8.8) | 0.47% | — | E-plugins Lawyer DirectoryAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Directory: from n/a through <= 1.3.3. | |
| Aplazada | Alta (7.5) | 0.59% | — | Fuelthemes Werkstatt PluginAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes WerkStatt Plugin werkstatt-plugin allows PHP Local File Inclusion.This issue affects WerkStatt Plugin: from n/a through <= 1.6.6. | |
| Aplazada | Media (6.3) | 0.54% | — | Backstage Backend-plugin-apiAIBackstage Cli-commonAI | 21/1/2026 | 17/6/2026 | Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent… | |
| Aplazada | Alta (7.1) | 0.53% | — | Backstage Backend-defaultsAIBackstage Plugin-scaffolder-backendAIBackstage Plugin-scaffolder-nodeAI | 21/1/2026 | 15/7/2026 | Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log`… | |
| Aplazada | Alta (8.6) | 0.75% | — | Nodebb Plugin EmojiAI | 21/1/2026 | 17/6/2026 | NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file… |