Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.53% | — | A3rev Software Woocommerce Predictive SearchAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in a3rev Software WooCommerce Predictive Search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Predictive Search: from n/a through 5.8.0. | |
| Analizada | Media (6.9) | 0.33% | — | Amazon Opensearch Data Prepper | 12/12/2024 | 17/6/2026 | OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerability exists in the OpenTelemetry Logs source in Data Prepper starting inversion 2.1.0 and prior to version 2.10.2 where some custom authentication plugins will not perform… | |
| Analizada | Media (4.7) | 0.42% | — | Wp-dreams Ajax Search | 12/12/2024 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.3) | 0.42% | — | Searchiq | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SearchIQ SearchIQ searchiq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through <= 4.4. | |
| Aplazada | Media (4.3) | 0.41% | — | Yummywp Smart Woocommerce SearchAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in YummyWP Smart WooCommerce Search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WooCommerce Search: from n/a through 2.5.0. | |
| Analizada | Media (5.4) | 0.30% | — | Searchiq | 4/12/2024 | 17/6/2026 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Eyecix Jobsearch WP JOB BoardAI | 28/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.34% | — | Takashimatsuyama Posts SearchAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Search posts-search allows Stored XSS.This issue affects Posts Search: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.8) | 0.17% | — | HP PCAISoundresearch Secomn64AI | 12/11/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities. | |
| Aplazada | Media (6) | 0.14% | — | HP PC Audio PackageAISoundresearch Secomn64AI | 12/11/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities. | |
| Aplazada | Alta (7.1) | 0.27% | — | Labdav Search Order BY Product SKU FOR WoocommerceAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in labdav Search order by product SKU for WooCommerce search-order-by-product-sku-for-woocommerce allows Reflected XSS.This issue affects Search order by product SKU for WooCommerce: from n/a through <= 0.2. | |
| Aplazada | Alta (7.1) | 0.27% | — | Askewbrook Bing Search API IntegrationAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in askewbrook Bing Search API Integration abbs-bing-search allows Reflected XSS.This issue affects Bing Search API Integration: from n/a through <= 0.3.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Gopiplus Twitter Real Time Search ScrollingAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Twitter real time search scrolling twitter-real-time-search-scrolling allows Reflected XSS.This issue affects Twitter real time search scrolling: from n/a through <= 7.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | TRE Technology AND Research Hq60 Fidelity CardAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TRe Technology And Research S.r.l. HQ60 Fidelity Card hq60-fidelity-card allows Reflected XSS.This issue affects HQ60 Fidelity Card: from n/a through <= 1.8. | |
| Analizada | Crítica (9.8) | 0.86% | — | Eyecix Jobsearch WP JOB Board | 6/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.79% | — | Eyecix Jobsearch WP JOB Board | 6/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Analizada | Crítica (9.8) | 0.43% | — | Eyecix Jobsearch WP JOB Board | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4. | |
| Analizada | Alta (8.8) | 0.38% | — | Eyecix Jobsearch WP JOB Board | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4. | |
| Aplazada | Media (4.3) | 0.36% | — | Cornelraiu WP Search AnalyticsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Cornel Raiu WP Search Analytics search-analytics.This issue affects WP Search Analytics: from n/a through <= 1.4.9. | |
| Aplazada | Media (4.3) | 0.37% | — | Epsiloncool WP Fast Total SearchAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232. | |
| Aplazada | Media (4.3) | 0.17% | — | Eyecix JobsearchAI | 31/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3. | |
| Modificada | Media (6.1) | 0.29% | — | Agustinberasategui AB Categories Search Widget | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ajberasategui AB Categories Search Widget ab-categories-search-widget allows Reflected XSS.This issue affects AB Categories Search Widget : from n/a through <= 0.2.5. | |
| Modificada | Media (6.1) | 0.29% | — | Dh9sb.dx-info Adif LOG Search Widget | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emka73 ADIF Log Search Widget adif-log-search-widget allows Reflected XSS.This issue affects ADIF Log Search Widget: from n/a through <= 1.0f. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Takayukii ACF Images Search AND InsertAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through <= 1.1.4. | |
| Modificada | Crítica (9.8) | 0.55% | — | Eyecix Jobsearch WP JOB Board | 10/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9. |