Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 350 respecto a la semana anterior
Críticas / altas1260▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.39% | — | Webberzone Better Search | 1/7/2023 | 17/6/2026 | El plugin Better Search para WordPress es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF) en versiones hasta la 2.5.2 inclusive. Esto se debe a la falta o incorrecta validación nonce en las funciones "bsearch_process_settings_import()" y "bsearch_process_settings_export()". Esto hace posible que… | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Searchwidget | 28/6/2023 | 17/6/2026 | Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity. | |
| Modificada | Media (6.1) | 0.34% | — | Faceted Search Project Faceted Search | 16/6/2023 | 17/6/2026 | The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data. | |
| Modificada | Media (4.4) | 0.54% | — | Advanced-woo-search Advanced WOO Search | 9/6/2023 | 17/6/2026 | The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.4) | 0.56% | — | Fibosearch | 9/6/2023 | 17/6/2026 | The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Media (4.3) | 0.46% | — | Webberzone Better Search | 7/6/2023 | 17/6/2026 | The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Modificada | Media (4.3) | 0.70% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls. | |
| Modificada | Alta (8.8) | 1.2% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site. | |
| Modificada | Media (5.3) | 0.85% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin. | |
| Modificada | Media (6.1) | 0.62% | — | Local Service Search Engine Management System Project Local Service Search Engine Management System | 31/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input… | |
| Modificada | Alta (8.8) | 0.26% | 💥 PoC | Internet-formation Wp-advanced-search | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Webhammer WP Custom Fields Search | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Prestashop Possearchproducts | 12/5/2023 | 17/6/2026 | Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). | |
| Modificada | Media (4.8) | 0.37% | — | WP Search Analytics Project WP Search Analytics | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.5 versions. | |
| Modificada | Media (5.9) | 0.46% | — | Amazon OpensearchAmazon Opensearch Security | 8/5/2023 | 17/6/2026 | OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to… | |
| Modificada | Media (6.1) | 0.46% | — | Wp-dreams Ajax Search | 24/4/2023 | 17/6/2026 | The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.49% | — | Wp-dreams Ajax Search | 24/4/2023 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.36% | — | Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Lucene-search | 12/4/2023 | 17/6/2026 | Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database. | |
| Modificada | Alta (7.8) | 0.38% | — | Vxsearch VX Search | 16/3/2023 | 17/6/2026 | VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file. | |
| Modificada | Alta (7.5) | 0.55% | — | Ajax Search Project Ajax Search | 15/3/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions. | |
| Modificada | Media (5.3) | 0.33% | — | Amazon OpensearchAmazon Opensearch Security | 2/3/2023 | 17/6/2026 | OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity… | |
| Modificada | Media (6.1) | 0.49% | — | Yellowyard Yellow Yard Searchbar | 8/2/2023 | 17/6/2026 | The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back to the user, leading to Reflected Cross-Site Scripting |