Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 350 respecto a la semana anterior
Críticas / altas1260▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

1096 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.39%—Webberzone Better Search1/7/202317/6/2026
El plugin Better Search para WordPress es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF) en versiones hasta la 2.5.2 inclusive. Esto se debe a la falta o incorrecta validación nonce en las funciones "bsearch_process_settings_import()" y "bsearch_process_settings_export()". Esto hace posible que…
ModificadaAlta (7.8)0.21%—Samsung Searchwidget28/6/202317/6/2026
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
ModificadaMedia (6.1)0.34%—Faceted Search Project Faceted Search16/6/202317/6/2026
The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data.
ModificadaMedia (4.4)0.54%—Advanced-woo-search Advanced WOO Search9/6/202317/6/2026
The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
ModificadaMedia (4.4)0.56%—Fibosearch9/6/202317/6/2026
The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaAlta (8.8)1.4%—Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+67/6/202317/6/2026
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
ModificadaMedia (4.3)0.46%—Webberzone Better Search7/6/202317/6/2026
The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
ModificadaMedia (4.3)0.70%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
ModificadaAlta (8.8)1.2%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
ModificadaMedia (5.3)0.85%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
ModificadaMedia (6.1)0.62%—Local Service Search Engine Management System Project Local Service Search Engine Management System31/5/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input…
ModificadaAlta (8.8)0.26%💥 PoCInternet-formation Wp-advanced-search24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.
ModificadaMedia (4.8)0.37%—Webhammer WP Custom Fields Search18/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions.
ModificadaCrítica (9.8)2.7%💥 ExploitPrestashop Possearchproducts12/5/202317/6/2026
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
ModificadaMedia (4.8)0.37%—WP Search Analytics Project WP Search Analytics10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.5 versions.
ModificadaMedia (5.9)0.46%—Amazon OpensearchAmazon Opensearch Security8/5/202317/6/2026
OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to…
ModificadaMedia (6.1)0.46%—Wp-dreams Ajax Search24/4/202317/6/2026
The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.49%—Wp-dreams Ajax Search24/4/202317/6/2026
The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.4)0.36%—Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter23/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions.
ModificadaMedia (4.3)0.35%—Jenkins Lucene-search12/4/202317/6/2026
Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.
ModificadaAlta (7.8)0.38%—Vxsearch VX Search16/3/202317/6/2026
VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.
ModificadaAlta (7.5)0.55%—Ajax Search Project Ajax Search15/3/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.
ModificadaMedia (5.3)0.33%—Amazon OpensearchAmazon Opensearch Security2/3/202317/6/2026
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity…
ModificadaMedia (6.1)0.49%—Yellowyard Yellow Yard Searchbar8/2/202317/6/2026
The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting