Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.33%—Kraftplugins Mega Elements15/5/202417/6/2026
The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.52%—Smartypantsplugins SP Project & Document Manager15/5/202417/6/2026
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
AnalizadaMedia (6.5)0.43%—Smartypantsplugins SP Project & Document Manager15/5/202417/6/2026
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
AplazadaMedia (6.4)0.46%—Bplugins Html5 Audio PlayerAI14/5/202417/6/2026
The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (4.3)0.25%—Warfareplugins Social WarfareAI14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1.
AplazadaAlta (8.8)1.6%—Plugins360 All-in-one Video GalleryAI2/5/202417/6/2026
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers, with contributor access and…
AplazadaMedia (4.3)0.56%—Pickplugins Post GridAI2/5/202417/6/2026
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtTPGSaveSettings function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.42%—Warfareplugins Social WarfareAI2/5/202417/6/2026
The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (5.3)0.38%—Fivestarplugins Five Star Restaurant ReservationsAI29/4/202417/6/2026
Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.
AplazadaMedia (5.3)0.52%—Realbigplugins Client DashAI29/4/202417/6/2026
Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.
AplazadaAlta (7.5)0.55%—Solid Plugins Solid AffiliateAI29/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.
AplazadaAlta (7.1)0.18%—Toast Plugins Sticky AnythingAI29/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything: from n/a through 2.1.5.
AplazadaCrítica (9.9)0.66%—Eazyplugins Eazy Plugin ManagerAI25/4/202417/6/2026
Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Eazy Plugin Manager: from n/a through 4.1.2.
AplazadaAlta (7.5)0.68%—Pickplugins Post GridAI24/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid.This issue affects Post Grid: from n/a through 2.2.78.
AplazadaMedia (5.5)0.33%—Really-simple-plugins Really Simple SSLAI18/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3.
ModificadaMedia (5.4)0.32%—Kraftplugins Mega Elements18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.1.9.
AplazadaMedia (4.3)0.30%—Verygoodplugins Fatal Error NotifyAI16/4/202417/6/2026
Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from n/a through 1.5.2.
ModificadaMedia (4.3)0.75%💥 PoCXlplugins Nextmove15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1.
AplazadaMedia (4.3)0.21%—Goldplugins Before AND AfterAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Gold Plugins Before And After.This issue affects Before And After: from n/a through 3.9.
ModificadaAlta (8.8)0.24%—Cleverplugins SEO Booster15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cleverplugins.Com SEO Booster.This issue affects SEO Booster: from n/a through 3.8.9.
ModificadaMedia (6.1)0.35%—Ezplugins EZ Form Calculator15/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenies EZ Form Calculator allows Reflected XSS.This issue affects EZ Form Calculator: from n/a through 2.14.0.3.
AplazadaMedia (5.4)0.20%—Catchplugins Generate Child ThemeAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Catch Plugins Generate Child Theme.This issue affects Generate Child Theme: from n/a through 2.0.
AplazadaMedia (5.4)0.20%—Quick-plugins Loan Repayment Calculator AND Application FormAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4.
AnalizadaMedia (5.4)17%💥 ExploitPickplugins Post Grid11/4/202417/6/2026
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts
ModificadaMedia (4.3)0.21%—Xlplugins Finale11/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.