Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Online Travel Agency System Project Online Travel Agency System | 17/8/2023 | 17/6/2026 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php. | |
| Modificada | Media (4.3) | 0.70% | — | Mooveagency Gdpr Cookie Compliance | 7/6/2023 | 17/6/2026 | The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings. | |
| Modificada | Media (5.4) | 0.38% | — | Webhelpagency WHA Puzzle | 18/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Webhelpagency WHA Crossword | 23/9/2022 | 17/6/2026 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPress. | |
| Modificada | Media (5.4) | 0.50% | — | Webhelpagency WHA Wordsearch | 21/9/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game plugin <= 2.0.1 at WordPress. | |
| Modificada | Media (5.4) | 0.68% | — | Webhelpagency WHA Crossword | 21/9/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.10 at WordPress. | |
| Modificada | Media (4.8) | 0.55% | — | Webhelpagency Word Search Puzzles | 9/9/2022 | 17/6/2026 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.1 at WordPress. | |
| Modificada | Crítica (9.8) | 0.79% | — | GAS Agency Management System Project GAS Agency Management System | 12/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.89% | — | GAS Agency Management System Project GAS Agency Management System | 12/8/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functionality of the file /gasmark/assets/myimages/oneWord.php. The manipulation of the argument shell leads to unrestricted upload. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Crítica (9.1) | 15% | 💥 Exploit | Mooveagency Import XML AND RSS Feeds | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action. | |
| Modificada | Media (6.1) | 10% | 💥 Exploit | Mooveagency Select ALL Categories AND Taxonomies, Change Checkbox TO Radio Buttons | 14/5/2021 | 17/6/2026 | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 14% | 💥 Exploit | Mooveagency Redirect 404 TO Parent | 14/5/2021 | 17/6/2026 | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 4.7% | 💥 Exploit | Mooveagency Contact Form Check Tester | 6/5/2021 | 17/6/2026 | The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and… | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (7.5) | 3.1% | — | Invento / Architecture Building Agency Template Project Invento / Architecture Building Agency Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Ijoomla AD Agency | 14/1/2018 | 17/6/2026 | The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php. | |
| Modificada | Alta (7.8) | 1.4% | — | Acquisition Technology AND Logistics Agency Installer OF Electronic Tendering | 7/7/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.5% | — | National TAX Agency E-tax | 22/5/2017 | 17/6/2026 | Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (8.8) | 1.6% | — | Information-technology Promotion Agency Introduction TO Safe Website Operation | 28/4/2017 | 17/6/2026 | Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data. | |
| Modificada | Media (5.4) | 0.27% | — | Adp4u ADP Agency Immobiliare | 9/9/2014 | 17/6/2026 | The ADP AGENCY Immobiliare (aka com.wAdpagencyAndroid) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.3% | — | Escortwebsitedesign Escort-agency-cms | 23/9/2011 | 16/6/2026 | Escort Agency CMS (aka escort-agency-cms) allows remote attackers to obtain sensitive information via crafted array parameters in a request to a .php file, which reveals the installation path in an error message, as demonstrated by makethumb.php and certain other files. |